What we've been watching.
Recent supply-chain compromises across npm, PyPI, RubyGems, crates.io, Go modules, Packagist, NuGet, Open VSX, Docker Hub, and GitHub Actions. Curated from public vendor advisories. We list every version we can verify so the scanner picks them up directly: 3,609 package–version pairs across 152 incidents and counting.
- High18 Aug 202611 packages tracked
GitHub Advisory malware sweep - 2026-08-17 / 2026-08-18 batch (Sui blockchain `@mysten/*` typosquat days 4-5 continuation `sui-move-graphql`+`sui-move-rpc`+`sui-gql-core`+`bcs-core`+`bucket-protocol-sdk-v2`, Tinkoff BNPL dep-confusion tail `bnpl-blocks-independent-bnpl-search`, LEB128 encoding typosquat pair `leb128x`+`ulebkit`, generic CWE-506 boilerplate `blastradar`+`runtime-health`, PyPI `socks5901` Android `/sdcard/` Telegram-bot exfiltrator)
11 GHSA CWE-506 advisories across npm + PyPI in the 24h ending 2026-08-18 06:00 UTC. Headline: five-package Sui blockchain typosquat continuation (
sui-move-graphql,sui-move-rpc,sui-gql-core,bcs-core,bucket-protocol-sdk-v2) extends thesui-gql-client/sui-bcs-codec(08-11) andsui-gql/bcs-compact(08-12)@mysten/*typosquat register into day-4/5. Also:bnpl-blocks-independent-bnpl-search(Tinkoff dep-confusion tail),leb128x+ulebkitLEB128 typosquat pair,blastradar+runtime-healthgeneric boilerplate, and PyPIsocks5901Android-target Telegram-bot exfiltrator.npmPyPIAffected packages11 packages · 13 versions
- npmbcs-core1.0.0
- npmblastradar1.0.0
- npmbnpl-blocks-independent-bnpl-search1.0.0
- npmbucket-protocol-sdk-v21.0.0
- npmleb128x1.0.0
- npmruntime-health1.0.11.0.21.0.4
- PyPIsocks59011.0.0
- npmsui-gql-core1.0.0
- npmsui-move-graphql1.0.0
- npmsui-move-rpc1.0.0
- npmulebkit1.0.0
multi-2026-08-18-ghsa-malware-sweepSource advisory - npmbcs-core
- Medium17 Aug 20262 packages tracked
GitHub Advisory quiet-tail sweep - 2026-08-16 / 2026-08-17 (`@ai-vertical/ai-agent` npm generic-malware + `kb-ai` PyPI OpenSSF `setup.py`-install pentest dep-confusion demo)
Two-day quiet-tail after 08-15's 22-package burst: only two new GHSA advisories.
@ai-vertical/ai-agent@1.0.0,1.0.1(npm, GHSA-3248-8gvm-g9jv) has the generic malware boilerplate and no IOC.kb-ai@0.1.0,0.1.1(PyPI, GHSA-34mp-hr4q-qvh5) is an OpenSSFPROBABLY_PENTESTdemo overridingsetup.py installto exfil IP + username.npmPyPIAffected packages2 packages · 4 versions
- npm@ai-vertical/ai-agent1.0.01.0.1
- PyPIkb-ai0.1.00.1.1
multi-2026-08-17-ghsa-quiet-tailSource advisory - npm@ai-vertical/ai-agent
- High15 Aug 202622 packages tracked
GitHub Advisory npm CWE-506 sweep - 2026-08-15 batch (`@velliajs/discord` `discord.js` impersonator with hardcoded GitHub PAT + hidden `_verifyAuthorization` kill-switch, `akamai(js)-sensor` Google-Calendar invisible-Unicode C2 trio, HackerOne/Twilio `*-probe`/`*-poc` bug-bounty-canary droppers with live payloads, `depcruise-*` + `gunzip-js` `99.9.1` dependency-confusion canary, `@wololasod/tiny-id` RC4 Windows/Linux dropper, `@finaxis/common-js` Xelis miner, `*-vim` naming-canary pair, plus IP/webhook exfiltrators)
22 npm CWE-506 advisories published 2026-08-15 - the day's headline is
@velliajs/discord@1.0.3..1.0.7, adiscord.jsimpersonator with two live hardcoded GitHub PATs, an unpinned private-reposysframedependency the operator can hot-swap, and a hiddenClient.login()_verifyAuthorizationallowlist kill-switch. Same-day clusters include a 3-packageakamai(js)-sensorGoogle-Calendar-dead-drop trio using invisible-Unicode payloads, HackerOne/Twilio*-probe/*-pocbug-bounty-canary droppers with real credential exfil, adepcruise-*+gunzip-js99.9.1OpenSSF-domain-flagged canary group,@wololasod/tiny-idRC4 dropper,@finaxis/common-jsXelis miner,adxaaWordPress account-takeover, and a matching*-vimnaming-canary pair.npmAffected packages22 packages · 57 versions
- npm@finaxis/common-js0.3.00.3.10.3.20.3.30.3.4
- npm@openrepl/shared0.0.40.0.5
- npm@velliajs/discord1.0.31.0.41.0.51.0.61.0.7
- npm@wololasod/tiny-id0.1.00.1.10.1.20.1.3
- npmadxaa1.0.0
- npmakamai-sensor1.0.0
- npmakamaijs-sensor2.0.03.0.0
- npmakamaijs-sensorv13.0.0
- npmautbank-core99.0.099.0.2
- npmdepcruise-baseline99.9.1
- npmdepcruise-fmt99.9.1
- npmdepcruise-wrap-stream-in-html99.9.1
- npmfastly-vcl-language-client1.0.0
- npmgunzip-js99.9.1
- npmharmony-app-toolkit21.0.022.0.0
- npmhunterone-build-probe-92101.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.7
- npmkit-hydration-vim1.0.0
- npmrequire-i18next20.0.021.0.0
- npmsvelte-goal-vim1.0.0
- npmtw-pkgprobe-77311.0.01.0.11.0.31.0.41.0.51.0.61.0.71.1.01.1.1
- npmtwilio-hackerone-poc-afe6937c1.0.01.0.11.0.21.0.31.0.4
- npmupload-to-gcp3.2.1
npm-2026-08-15-ghsa-malware-sweepSource advisory - npm@finaxis/common-js
- High14 Aug 202626 packages tracked
GitHub Advisory npm CWE-506 sweep - 2026-08-14 batch (~27 packages: `jchunt.top` telemetry-canary day-2 `xrblocks-mcp`, `preinstall-hook-webhook-callback-demo` webhook.site demo, `@secauditb20y/sec-test-r3b` self-labeled sec-test POC, `webautomation_js` + `@ferudionz/*` obfuscator.io RC4 runtime exfil trio, `@guangnao/agent-proxy` Claude/Codex credential monetizer to `hub.client-llm.com`, `@lodash-js/lodash-js` Xelis miner, `@divineubg/divine` ntfy.sh EventSource C2, `@demopack/www` iOS iframe exploit injector, `@ghost_debugger/nanocache` hidden Windows binary launcher, `datefmt-simple-utils` reverse shell to `8.135.48.40:4444`, `registrynpmjs.to` typosquat cluster (`@polymarkets/clob-client-v2`, `@devmikets/hyperliquid-sdk`), Brazilian `alelo-*` dep-confusion cluster to `209.99.185.109`, plus `@peptideventure/*`, `@mexc/shared-utils`, `sui-gql-lite`, `bcs-mini`)
~27 npm CWE-506 advisories published 2026-08-14 (initial 4 clusters backfilled 08-15 with 8 more). Headliners:
@guangnao/agent-proxyClaude/Codex credential monetiser tohub.client-llm.com,@lodash-js/lodash-jsXelis miner,@divineubg/divinentfy.sh EventSource C2,registrynpmjs.totyposquat pair (@polymarkets/clob-client-v2,@devmikets/hyperliquid-sdk), Brazilianalelo-*dep-confusion cluster to209.99.185.109,datefmt-simple-utilsreverse shell to8.135.48.40:4444,@ghost_debugger/nanocacheWindows binary launcher.npmAffected packages26 packages · 42 versions
- npm@demopack/www0.0.12
- npm@devmikets/hyperliquid-sdk1.9.6
- npm@divineubg/divine1.0.01.0.11.0.21.0.31.0.41.0.5
- npm@ferudionz/web_logger_js1.0.0
- npm@ferudionz/webautomation1.0.0
- npm@ghost_debugger/nanocache0.1.1
- npm@guangnao/agent-proxy1.2.11.4.01.4.2
- npm@lodash-js/lodash-js0.1.00.2.00.3.0
- npm@mexc/shared-utils1.0.0
- npm@peptideventure/peptide-score-modifier1.0.0
- npm@peptideventure/peptide-unit1.0.0
- npm@polymarkets/clob-client-v21.0.6
- npm@secauditb20y/sec-test-r3b1.0.0
- npmalelo-client99.0.099.0.2
- npmalelo-common99.0.0
- npmalelo-core99.0.099.0.199.0.2
- npmalelo-payment99.0.099.0.2
- npmalelo-services99.0.099.0.2
- npmalelo-utils99.0.0
- npmbcs-mini1.0.0
- npmdatefmt-simple-utils1.0.0
- npmmeualelo99.0.0
- npmpreinstall-hook-webhook-callback-demo1.0.01.0.1
- npmsui-gql-lite1.0.0
- npmwebautomation_js1.0.01.0.1
- npmxrblocks-mcp6.3.1
npm-2026-08-14-ghsa-malware-sweepSource advisory - npm@demopack/www
- Critical13 Aug 202646 packages tracked
GitHub Advisory npm CWE-506 sweep - 2026-08-13 batch (`ltidisafe` GCS dep-confusion dropper ring `check-audit`+`cspell-esm`+`eslint-publish-release`+`in-install`+`knip-bun`+`resolve-audit`+`napi-raw`, `31.97.137.157:45000` bare-IP Chromium-DPAPI stealer kit `vexium-kit`+`ventra-kit`+`velora-kit`+`vortex-kit`+`copytrade-core`+`prediction-trader`, `@hzero-front-ui/*` internal-scope dep-confusion 5-package cluster with `callback.m0chan.co.uk` DNS+HTTPS beacon, `@khaznatech/*` webhook.site preinstall exfil 3-pack, `jchunt.top` telemetry-canary series `wct-st`+`tizen-webdriver-cli`, `8.135.48.40:4444` reverse-shell date-fmt masquerade pair `datefmt-util-helper`+`date-fmt-helper-xz`, `notafollower` AWS IMDSv2 credential theft, `bs58-15` base58 typosquat via `base65-15x` transitive, `@solana-js/web3` Windows PowerShell + `files.catbox.moe` RCE, `postcss-initialize-plugin` Ethereum-RPC-C2 continuation, `mutex-forge` Telegram+Slack+Ethereum-Sepolia RAT, `chai-as-reformed`+`process-live-log`+`external-process-live-log`+`minimalistic-assert-plus` Function-constructor R-shell family, `node-config-svg-contract` eval-from-URL, `nc-verify-127942`+`@jacksher/install-exec-poc` OAST recon POCs, `cilm-ui-commons` pipedream.net preinstall, ~10 boilerplate CWE-506)
~50 npm CWE-506 advisories published 2026-08-13. Headline:
ltidisafeGCS dep-confusion dropper ring (7+ hollow-shell packages at v99.9.1 pinningltidisafeas anhttps://ltidi.storage.googleapis.com/depenconf/tarball to bypass npm registry review);31.97.137.157:45000bare-IP Chromium-DPAPI stealer kit family (vexium-kit,ventra-kit,velora-kit,vortex-kit,copytrade-core,prediction-trader- all fetch/icons/108|116andeval()acreditsfield with@primno/dpapi+better-sqlite3+node-machine-idbundled for browser-cred theft); and a *`@hzero-front-ui/5-package internal-scope dep-confusion cluster** beaconing tocallback.m0chan.co.uk`.npmAffected packages46 packages · 87 versions
- npm@hzero-front-ui/c7n-ui99.99.99
- npm@hzero-front-ui/cfg99.99.99
- npm@hzero-front-ui/core99.99.99
- npm@hzero-front-ui/hzero-ui99.99.99
- npm@hzero-front-ui/themes99.99.99
- npm@jacksher/install-exec-poc1.0.01.0.2
- npm@khaznatech/common99.0.0
- npm@khaznatech/core99.0.0
- npm@khaznatech/utils99.0.0
- npm@leonardo0902/vortex-kit12.0.2
- npm@solana-js/web31.91.3
- npmai-analyzer1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.111.0.121.0.131.0.141.0.151.0.161.0.171.0.181.0.19
- npmbs58-156.0.06.0.1
- npmchai-as-reformed1.2.0
- npmcheck-audit99.9.1
- npmcilm-ui-commons1.1.0
- npmcopytrade-core2.3.0
- npmcspell-esm99.9.1
- npmdate-fmt-helper-xz1.0.01.0.11.0.21.0.31.0.4
- npmdatefmt-util-helper1.0.01.0.1
- npmdebug-proxy-chrome-devtools1.0.11.0.2
- npmeslint-generate-prerelease99.9.1
- npmeslint-generate-release99.9.1
- npmeslint-publish-release99.9.1
- npmexternal-process-live-log13.5.2
- npmin-install99.9.1
- npmknip-bun99.9.1
- npmminimalistic-assert-plus1.1.7
- npmmutex-forge2.0.12.0.2
- npmnapi-raw99.9.1
- npmnc-verify-1279421.0.0
- npmnode-config-svg-contract1.0.0
- npmnotafollower1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.11
- npmpath-match-js1.0.0
- npmpostcss-initialize-plugin3.0.4
- npmprediction-trader2.3.0
- npmprocess-live-log11.5.2
- npmreact-shield1.0.0
- npmresolve-audit99.9.1
- npmroot-locator1.0.0
- npmsource-analyzer1.0.0
- npmtizen-webdriver-cli1.0.0
- npmvelora-kit12.0.212.1.2
- npmventra-kit1.0.2
- npmvexium-kit2.0.210.0.2
- npmwct-st1.0.0
npm-2026-08-13-ghsa-malware-sweepSource advisory - npm@hzero-front-ui/c7n-ui
- Critical12 Aug 2026159 packages tracked
GitHub Advisory npm CWE-506 sweep - 2026-08-12 batch (Web3 typosquat webhook.site ring day-2 `permit2`+`camelot-ammv2-*`+`boring-vault`+`augustdigital-sdk`+`upshift-*`, Ethereum-RPC-C2 `envpack-conf`+`tailwind-form-templates` XOR-encrypted second-stage on blockchain, `svelte-kit-vim`+`kit-map-vim` map-streak-kit day-4 continuation, `sui-gql`+`bcs-compact` Sui `@mysten/*` typosquat continuation, ~50-package `@years17/18/19/20/*` n8n-nodes-utils-helper red-team SSH-backdoor mass drop, `internallib_v756`/`v392` bare `/dev/tcp/10.0.74.63/4444` reverse shell, `mcp-util-helpers` webhook.site R-shell channel, `passkeys-react` Burp Collaborator OAST recon, `bb-twl-k7x2` Twilio-internal dep-confusion, `@telekom-ods/react-ui-kit` Deutsche Telekom internal-scope, `verify-cli`+`@assetshop/verify-cli` OAST recon pair, `dakumangalsingh` Java-Robot RAT with jpackage wrapper, boilerplate CWE-506 mass npm flood ~100 packages)
~160 npm CWE-506 advisories published 2026-08-12. Headline: Web3 typosquat webhook.site ring day-2 (
permit2,camelot-ammv2-core/periphery,boring-vault,augustdigital-sdk,upshift-finance/config) with identical env/wallet-keystore exfil TTP as the 08-11 OpenZeppelin/Aerodrome ring; Ethereum-RPC-C2 pair (envpack-conf,tailwind-form-templates) fetching XOR-encrypted second-stage from blockchain via wallet0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a; and a *~50-package `@years17/18/19/20/` red-team n8n mass drop** installing pwn@kali SSH backdoors.npmAffected packages159 packages · 184 versions
- npm@assetshop/verify-cli99.0.099.0.1
- npm@bikli/bikli1.0.0
- npm@bikli/cli1.0.0
- npm@noxzacode/eslint-config1.0.0
- npm@noxzacode/libsignal-node1.0.0
- npm@telekom-ods/react-ui-kit2.6.02.6.9
- npm@years17/n8n-nodes-helper-utils1.0.01.0.11.0.21.0.31.0.41.0.51.0.6
- npm@years17/n8n-nodes-utils-helper1.0.0
- npm@years17/n8n-nodes-utils-helper-b1.0.0
- npm@years17/n8n-nodes-utils-helper-c1.0.0
- npm@years17/n8n-nodes-utils-helper-d1.0.0
- npm@years17/n8n-nodes-utils-helper-e1.0.0
- npm@years17/n8n-nodes-utils-helper-f1.0.0
- npm@years17/n8n-nodes-utils-helper-g1.0.0
- npm@years17/n8n-nodes-utils-helper-h1.0.0
- npm@years17/n8n-nodes-utils-helper-i1.0.0
- npm@years18/n8n-nodes-utils-helper-a1.0.0
- npm@years18/n8n-nodes-utils-helper-b1.0.0
- npm@years18/n8n-nodes-utils-helper-c1.0.0
- npm@years18/n8n-nodes-utils-helper-d1.0.0
- npm@years18/n8n-nodes-utils-helper-e1.0.0
- npm@years18/n8n-nodes-utils-helper-f1.0.0
- npm@years18/n8n-nodes-utils-helper-g1.0.0
- npm@years18/n8n-nodes-utils-helper-j1.0.0
- npm@years18/n8n-nodes-utils-helper-k1.0.0
- npm@years18/n8n-nodes-utils-helper-l1.0.0
- npm@years18/n8n-nodes-utils-helper-m1.0.0
- npm@years18/n8n-nodes-utils-helper-n1.0.0
- npm@years18/n8n-nodes-utils-helper-o1.0.0
- npm@years18/n8n-nodes-utils-helper-p1.0.0
- npm@years18/n8n-nodes-utils-helper-q1.0.0
- npm@years18/n8n-nodes-utils-helper-r1.0.0
- npm@years18/n8n-nodes-utils-helper-s1.0.0
- npm@years18/n8n-nodes-utils-helper-t1.0.0
- npm@years18/n8n-nodes-utils-helper-u1.0.0
- npm@years18/n8n-nodes-utils-helper-v1.0.0
- npm@years18/n8n-nodes-utils-helper-w1.0.0
- npm@years18/n8n-nodes-utils-helper-x1.0.0
- npm@years18/n8n-nodes-utils-helper-y1.0.0
- npm@years19/n8n-nodes-utils-helper-a1.0.0
- npm@years19/n8n-nodes-utils-helper-b1.0.0
- npm@years19/n8n-nodes-utils-helper-c1.0.0
- npm@years19/n8n-nodes-utils-helper-d1.0.0
- npm@years19/n8n-nodes-utils-helper-e1.0.0
- npm@years19/n8n-nodes-utils-helper-f1.0.0
- npm@years19/n8n-nodes-utils-helper-g1.0.0
- npm@years19/n8n-nodes-utils-helper-h1.0.0
- npm@years19/n8n-nodes-utils-helper-i1.0.0
- npm@years19/n8n-nodes-utils-helper-j1.0.0
- npm@years19/n8n-nodes-utils-helper-k1.0.0
- npm@years19/n8n-nodes-utils-helper-l1.0.0
- npm@years19/n8n-nodes-utils-helper-m1.0.0
- npm@years19/n8n-nodes-utils-helper-n1.0.0
- npm@years19/n8n-nodes-utils-helper-o1.0.0
- npm@years19/n8n-nodes-utils-helper-p1.0.0
- npm@years19/n8n-nodes-utils-helper-q1.0.0
- npm@years19/n8n-nodes-utils-helper-r1.0.0
- npm@years19/n8n-nodes-utils-helper-s1.0.0
- npm@years19/n8n-nodes-utils-helper-t1.0.0
- npm@years19/n8n-nodes-utils-helper-u1.0.0
- npm@years19/n8n-nodes-utils-helper-v1.0.0
- npm@years19/n8n-nodes-utils-helper-w1.0.0
- npm@years19/n8n-nodes-utils-helper-x1.0.0
- npm@years19/n8n-nodes-utils-helper-y1.0.0
- npm@years20/n8n-nodes-utils-helper-a1.0.0
- npm@years20/n8n-nodes-utils-helper-b1.0.0
- npm@years20/n8n-nodes-utils-helper-c1.0.0
- npm@years20/n8n-nodes-utils-helper-d1.0.0
- npm@years20/n8n-nodes-utils-helper-e1.0.0
- npm@years20/n8n-nodes-utils-helper-f1.0.0
- npm@years20/n8n-nodes-utils-helper-g1.0.0
- npm@years20/n8n-nodes-utils-helper-h1.0.0
- npm@years20/n8n-nodes-utils-helper-i1.0.0
- npm@years20/n8n-nodes-utils-helper-j1.0.0
- npmairdzticket1.0.0
- npmaugustdigital-sdk8.20.1
- npmbb-twl-k7x21.0.01.0.1
- npmbcnfjndwbkf21.0.0
- npmbcs-compact1.0.0
- npmbgncvhferucfds1.0.0
- npmbgzxcuite21.0.0
- npmbiklimaster1.0.0
- npmbiklirouter1.0.0
- npmbikliwrapper1.0.0
- npmbmgki3g6fh31.0.0
- npmboring-vault1.0.01.1.01.1.1
- npmbvdfhdfvnk31.0.0
- npmcamelot-ammv2-core1.0.01.1.01.1.1
- npmcamelot-ammv2-periphery1.0.01.1.01.1.1
- npmchina_airlines1.0.0
- npmchmjdsidwlf51.0.0
- npmcjdfswifuem31.0.0
- npmclxofwfjskaz71.0.0
- npmcsbcldfvivwfgd41.0.0
- npmcvbmxiowkwqla61.0.0
- npmcvbniydplwe31.0.0
- npmcvjwyinkpas1.0.0
- npmcvmbxcjiasdg1.0.0
- npmcvvkshuelwiu1.0.0
- npmcxcbdjxcmncvfg21.0.0
- npmdakumangalsingh1.0.01.0.11.1.0
- npmdhjksficgwu21.0.0
- npmdzcvhfruwluwe1.0.0
- npmdzvchorehui21.0.0
- npmegair08101.0.0
- npmegypt08111.0.0
- npmenvpack-conf1.0.1
- npmfdhcvriwecv31.0.0
- npmfghvbmniwu1.0.0
- npmfhj8cv9dkwm41.0.0
- npmgdwkh6vcbu1.0.0
- npmhcfguyfrmblp1.0.0
- npmhfkcdyuwbdx11.0.0
- npmhgdvfuflnb1.0.0
- npmhlksdcixycvf1.0.0
- npmhngfykuvgh41.0.0
- npmhxckdoeaqjlc81.0.0
- npminternallib_v3921.0.0
- npminternallib_v7561.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.7
- npmjhkxcixudnvm11.0.0
- npmjkbnwsdf81.0.0
- npmkanyut1.0.0
- npmkhanbmnxls1.0.0
- npmkit-map-vim1.0.0
- npmmcp-util-helpers1.0.0
- npmmnchfnvbue11.0.0
- npmmnhdjoweuq1.0.0
- npmmnmobicom1.0.0
- npmmnteckets1.0.0
- npmmnzjgxciwadk1.0.0
- npmmobicommn1.0.0
- npmmobicwkgjmx1.0.0
- npmms_aidc_com_tw1.0.0
- npmnhdxzthponv51.0.0
- npmnihzvdeowx51.0.0
- npmnoxleys1.0.0
- npmpasskeys-react1.0.1
- npmpassport8111.0.0
- npmpermit21.0.01.0.1
- npmprezdentkxheiw1.0.0
- npmsui-gql1.0.0
- npmsvelte-kit-vim1.0.0
- npmtailwind-form-templates0.7.4
- npmthundertiger1.0.0
- npmtruecxikdsal1.0.0
- npmtwcvhjlksdmx1.0.0
- npmunitel31.0.0
- npmunitel41.0.0
- npmupshift-config0.5.14
- npmupshift-finance1.0.0
- npmvczxijghsvizu41.0.0
- npmverify-cli99.0.0
- npmvfgnhlkxchrd1.0.0
- npmvkldhcmieru61.0.0
- npmvlbhvgovbbhfab1.0.0
- npmxcnvjfsiewlk91.0.0
- npmxhjckswqivb1.0.0
- npmyangming7081.0.0
- npmyangming81.0.0
npm-2026-08-12-ghsa-malware-sweepSource advisory - npm@assetshop/verify-cli
- Critical11 Aug 202638 packages tracked
GitHub Advisory npm CWE-506 sweep - 2026-08-11 batch (webhook.site Web3 typosquat credential-theft ring `@openzeppelin-4/5/contracts`+`@aerodrome-finance/contracts`+`@aerodrome-finance/slipstream`+`ethereum-vault-connector`, `safe-local-env-loader` env-local RAT sibling, `newtun` unencrypted-WebSocket PTY RAT with self-update, `svelte-vim-kit`+`kit-vim-map` map-streak-kit family continuation, `@nzeros/codebreak` Go ELF disguised as C solver, `base65-*` base-x typosquat cluster with 123KB obfuscated payload + `bs58-*` boilerplate siblings, coordinated `oastify.com`/`sslip.io`/webhook OAST dep-confusion recon beacons)
38 npm CWE-506 advisories published 2026-08-11. Headline: five-package Web3 typosquat ring (
@openzeppelin-4/contracts,@openzeppelin-5/contracts,@aerodrome-finance/contracts,@aerodrome-finance/slipstream,ethereum-vault-connector) sharing the samewebhook.sitecredential-exfil TTP with 60-240s detached-process delay + sandbox evasion,safe-local-env-loadercontinuing the 2026-08-10env-localWindows RAT, andnewtunshipping a PTY reverse shell with self-update.npmAffected packages38 packages · 117 versions
- npm@aerodrome-finance/contracts1.0.01.1.01.1.1
- npm@aerodrome-finance/slipstream1.0.01.1.01.1.1
- npm@dgn-src-click-to-pay-org/srcdcfreleasecert999.0.1
- npm@nzeros/codebreak1.3.0
- npm@openzeppelin-4/contracts1.0.01.0.1
- npm@openzeppelin-5/contracts1.0.01.0.1
- npmbase65-11x1.0.02.0.03.0.04.0.04.0.15.0.05.0.15.0.2
- npmbase65-12x1.0.02.0.03.0.04.0.04.0.15.0.05.0.15.0.2
- npmbase65-13x1.0.02.0.03.0.04.0.04.0.15.0.05.0.15.0.2
- npmbase65-15x1.0.02.0.03.0.04.0.04.0.15.0.05.0.15.0.2
- npmbase65-33x1.0.02.0.03.0.04.0.04.0.15.0.05.0.15.0.2
- npmbase65-77x1.0.02.0.03.0.04.0.04.0.15.0.05.0.15.0.2
- npmbjm-low-code-components99.0.0
- npmbs58-111.0.0
- npmbs58-121.0.0
- npmbs58-131.0.0
- npmchapters-core9.999.999
- npmdakumangalsingh_virus1.0.01.2.01.3.0
- npmdcfarguscert999.0.1
- npmdependencyfsdsfdsfg99.9.0
- npmdeveloper-dashboard1.0.0
- npmethereum-vault-connector1.0.01.1.01.1.1
- npmfetch-runtime1.0.0
- npmghazaly99.9.0
- npminternallib_v1641.0.0
- npmkit-vim-map1.0.0
- npmlines-columns1.0.0
- npmnewtun1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.111.0.121.0.131.0.141.0.151.0.161.0.171.0.181.0.191.0.201.0.211.0.221.0.231.0.241.0.251.0.261.0.27
- npmnode-internal-svg-loader1.0.0
- npmsafe-local-env-loader1.0.0
- npmsui-bcs-codec1.0.0
- npmsui-gql-client1.0.0
- npmsvelte-vim-kit1.0.0
- npmtilaver-mfa1.0.0
- npmtsihealth-client1.0.0
- npmvite-svg-parse1.0.0
- npmwhs4_ued1.0.0
- npmzeal-rq-hooks0.0.0
npm-2026-08-11-ghsa-malware-sweepSource advisory - npm@aerodrome-finance/contracts
- Critical11 Aug 20267 packages tracked
GitHub Advisory PyPI CWE-506 sweep - 2026-08-11 batch (`joule-sbx-poc`+`joule-btp-extension` 2026-08-joule-btp-extension localhost-exfil + reverse-shell PROBABLY_PENTEST pair, `telebot-pro` 2026-08-telebot-pro Telegram-session hidden-thread infostealer, `euler-sdk`+`morpho-sdk` GENERIC-standard-pypi-install-pentest setup.py install-hook IP+username exfil, `dlmm-sdk`+`dlmm` 2026-08-dlmm MALICIOUS env-var + credential + crypto wallet-directory enumeration)
7 PyPI CWE-506 advisories published 2026-08-11 across four named campaigns: 2026-08-telebot-pro starts a hidden exfiltration thread that lifts Telegram session files, pictures, and connected WiFi network info; 2026-08-dlmm exfiltrates env vars + credentials + cryptocurrency wallet directory listings on import; 2026-08-joule-btp-extension +
euler-sdk/morpho-sdkare PROBABLY_PENTEST setup.py install-hook recon packages targeting DeFi vendor namespaces.PyPIAffected packages7 packages · 14 versions
- PyPIdlmm1.0.0
- PyPIdlmm-sdk1.0.0
- PyPIeuler-sdk1.0.0
- PyPIjoule-btp-extension0.1.00.1.10.1.20.1.30.1.40.1.50.1.6
- PyPIjoule-sbx-poc0.1.0
- PyPImorpho-sdk1.0.0
- PyPItelebot-pro2.3.72.3.8
pypi-2026-08-11-ghsa-malware-sweepSource advisory - PyPIdlmm
- Critical10 Aug 202642 packages tracked
GitHub Advisory npm CWE-506 sweep - 2026-08-10 batch (`iconova-react` + `postcss-initial-provider` on-chain Ethereum RPC dead-drop C2 loader pair, `svelte-kit-streak`+`kit-map-streak` Linux implant continuation of the map-streak-kit family, `@rblxts/services` catbox.moe Windows RAT sibling of last week's `@rbx-ts/services`, `@kuperka/chainguard-sdk` browser-form + wallet exfil, `xerohub-discord-voice` Discord-token stealer, `env-local` Windows persistent screen-capture + remote control, `hex-encode-utils` Cloudflare-Workers AES-GCM Python-payload loader, `cryptostock`/`tokocrytodev` Infura wallet-drainer, `simple-date-formatter-new-9/10` bash reverse shell to 124.221.154.135:4444, `polymarket-stake-mathss` log-taker.store loader, `chai-tracker` chai-spies impersonator with `dbconnectify` C2, `@noobaihome/amis-*-area-widget` Baidu-internal dep-confusion SSRF probe, and multi-vendor SQLite/postcss/commonjs/eth-library typosquat clusters)
46 npm CWE-506 advisories published 2026-08-10. Standouts:
iconova-react+postcss-initial-provideruse Ethereum RPC on-chain dead-drop C2 to fetch stage-2 IP addresses (same EtherHiding technique as the CHAINDROP keyv/cacheable worm);svelte-kit-streak+kit-map-streakcontinue themap-streak-kitLinux-implant family;env-localinstalls a Windows registry-persisted screen-capture + remote-control implant impersonating dotenv.npmAffected packages42 packages · 74 versions
- npm@kuperka/chainguard-sdk1.0.11.0.2
- npm@noobaihome/amis-simple-area-widget1.0.0
- npm@noobaihome/amis-uni-area-widget1.0.0
- npm@rblxts/services1.6.01.6.2
- npm@sqlite-labs/createsql1.0.0
- npm@sqlite-labs/nodesql1.0.0
- npm@sqlite-prime/createsql1.0.0
- npm@sqlite-prime/nodesql1.0.0
- npm@sqlite-table/schema-generator1.0.0
- npm@sqlite-table/sql-creator1.0.0
- npm@ssgw/icon9.999.999
- npmchai-as-bench1.0.0
- npmchai-as-deployer1.0.0
- npmchai-as-format1.0.0
- npmchai-as-map1.0.0
- npmchai-as-promised-plus1.0.0
- npmchai-jsonss1.0.0
- npmchai-tracker1.1.01.1.11.1.21.1.31.2.1
- npmcommonjs-assert1.0.0
- npmcommonjs-assertion1.0.0
- npmcryptostock1.0.01.0.1
- npmenv-local18.4.018.4.118.4.2
- npmeth-library-toolkit1.0.0
- npmeth-library-utils1.0.0
- npmfsbrowse0.2.28
- npmgodot-kit1.0.1786316795
- npmhex-encode-utils1.0.01.0.11.0.21.0.31.0.41.0.5
- npmiconova-react1.30.01.30.1
- npmkit-map-streak1.0.0
- npmneverthrow-js1.0.0
- npmpolymarket-stake-mathss1.0.02.0.03.0.03.5.03.5.13.5.2
- npmpost-css-transfer1.0.0
- npmpostcss-initial-provider1.0.02.0.03.0.03.0.13.0.23.0.33.0.4
- npmpostcss-theme-provider1.0.0
- npmruntimekit1.0.0
- npmsimple-date-formatter-new-101.0.0
- npmsimple-date-formatter-new-91.0.0
- npmspoint0.1.6950.1.6960.1.6970.1.6980.1.6990.1.700
- npmsvelte-kit-streak1.0.0
- npmtailwind-elements-ui1.0.0
- npmtokocrytodev1.0.0
- npmxerohub-discord-voice1.0.01.0.1
npm-2026-08-10-ghsa-malware-sweepSource advisory - npm@kuperka/chainguard-sdk
- Critical10 Aug 202611 packages tracked
GitHub Advisory PyPI CWE-506 sweep - 2026-08-09..2026-08-11 batch (`neutrl-core`+`neutrl-contracts`+`plp-contract` credential-stealing dep-hidden campaign 2026-08-neutrl-core, `kotanku`+`kotoraka`+`btcflx`+`btcflip` Telegram-bot wallet-file exfiltrator quartet 2026-08-kotanku campaign, `pytablute` 2025-11-spellcheckers multi-stage RCE + polling C2, `chaintest` DPRK Contagious-Interview-adjacent browser+wallet+clipboard+SSH-key infostealer, `bigtime` open()-hook file-write exfiltrator 2026-08-bigtime campaign, `cubesat-upstream-driver` env-var reconnaissance dep-confusion PROBABLY_PENTEST)
11 PyPI CWE-506 advisories published 2026-08-09..2026-08-11 across four named campaigns: 2026-08-neutrl-core hides credential theft in an intentional malicious dependency (fake backdated GitHub history); 2026-08-kotanku ships four Telegram-bot cryptocurrency-wallet-file exfiltrators (
kotanku,kotoraka,btcflx,btcflip); 2025-11-spellcheckers multi-stage RCE lands aspytablute;chaintestis a DPRK "Contagious Interview"-adjacent full-spectrum stealer.PyPIAffected packages11 packages · 20 versions
- PyPIbigtime0.1.0
- PyPIbtcflip0.1.0
- PyPIbtcflx0.1.0
- PyPIchaintest0.1.0
- PyPIcubesat-upstream-driver1.0.1
- PyPIkotanku0.1.0
- PyPIkotoraka0.1.0
- PyPIneutrl-contracts2.0.02.0.12.0.2
- PyPIneutrl-core2.0.02.0.12.0.2
- PyPIplp-contract2.0.02.0.12.0.2
- PyPIpytablute1.0.01.0.11.0.21.0.3
pypi-2026-08-10-ghsa-malware-sweepSource advisory - PyPIbigtime
- Critical8 Aug 202647 packages tracked
GitHub Advisory npm CWE-506 sweep - 36-package 2026-08-08 batch (`sme-rko-finance-front-*` 30-package Tinkoff/T-Bank RKO SME dep-confusion cluster running WEL1DROPPER-style cross-platform Cloudflare-Workers dropper + `@coralxyz/anchor` Solana Anchor typosquat with PowerShell zip drop + `titan-exchange-shared-permissions@99.9.9` dep-confusion recon + `@rbx-ts/services` Roblox-TS typosquat catbox.moe RAT + `map-streak-kit` Linux implant with systemd persistence + `localization-fixer`/`modern-localization` jsonbin.io mutable-payload loader pair)
36 npm CWE-506 advisories 2026-08-08: 30-package
sme-rko-finance-front-*Tinkoff/T-Bank RKO dep-confusion cluster (v35.8.1, WEL1DROPPER-style Cloudflare-Workers dropper) plus outliers@coralxyz/anchorSolana typosquat,titan-exchange-shared-permissions@99.9.9recon,@rbx-ts/services,map-streak-kitLinux implant, and alocalization-fixer+modern-localizationjsonbin.io loader pair.npmAffected packages47 packages · 53 versions
- npm@coralxyz/anchor0.30.00.30.10.30.2
- npm@rbx-ts/services1.6.0
- npmbnpl-blocks-desktop-bnpl-anchor-title35.2.5
- npmlocalization-fixer1.0.01.0.11.1.01.1.1
- npmmap-streak-kit1.0.0
- npmmodern-localization1.1.11.2.1
- npmsme-rko-finance-front-operations-domain35.8.1
- npmsme-rko-finance-front-operations-fee35.8.1
- npmsme-rko-finance-front-operations-feed-impl35.8.1
- npmsme-rko-finance-front-operations-feed-models35.8.1
- npmsme-rko-finance-front-operations-holding-domain35.8.1
- npmsme-rko-finance-front-operations-income35.8.1
- npmsme-rko-finance-front-operations-notifications-impl35.8.1
- npmsme-rko-finance-front-operations-notifications-models35.8.1
- npmsme-rko-finance-front-operations-other35.8.1
- npmsme-rko-finance-front-operations-overnight35.8.1
- npmsme-rko-finance-front-operations-pegasus35.8.1
- npmsme-rko-finance-front-operations-penalty35.8.1
- npmsme-rko-finance-front-operations-providers35.8.1
- npmsme-rko-finance-front-operations-shared35.8.1
- npmsme-rko-finance-front-operations-special-payments35.8.1
- npmsme-rko-finance-front-operations-tax35.8.1
- npmsme-rko-finance-front-operations-widget-domain35.8.1
- npmsme-rko-finance-front-operations-widget-impl35.8.1
- npmsme-rko-finance-front-operations-widget-models35.8.1
- npmsme-rko-finance-front-payment-registers-operations-domain35.8.1
- npmsme-rko-finance-front-payments-allowed-tariffs-filter35.8.1
- npmsme-rko-finance-front-payments-classic-payment-actions-operations-repeat-impl35.8.1
- npmsme-rko-finance-front-payments-classic-payment-actions-operations-repeat-models35.8.1
- npmsme-rko-finance-front-payments-currency-payment-actions-operations-repeat-impl35.8.1
- npmsme-rko-finance-front-payments-currency-payment-actions-operations-repeat-models35.8.1
- npmsme-rko-finance-front-payments-currency-payment-domain35.8.1
- npmsme-rko-finance-front-payments-domain35.8.1
- npmsme-rko-finance-front-payments-feed-adapter35.8.1
- npmsme-rko-finance-front-payments-feed-display-list35.8.1
- npmsme-rko-finance-front-payments-feed-display-list-impl35.8.1
- npmspecials-resources-server35.8.1
- npmstatist-browser-typed-client-eventea.projects.pwafamily35.8.0
- npmstatist-browser-typed-client-eventea.projects.pwahelp35.8.0
- npmstatist-browser-typed-client-eventea.projects.pwainsurance0.0.1
- npmstatist-browser-typed-client-eventea.projects.pwakasko0.0.1
- npmstatist-browser-typed-client-eventea.projects.tdeal0.0.1
- npmstatist-browser-typed-client-eventea.projects.tdevice0.0.1
- npmstreak-map-kit1.0.0
- npmsvelte-kit-cache1.0.0
- npmsvelte-streak-kit1.0.0
- npmtitan-exchange-shared-permissions99.9.9
npm-2026-08-08-ghsa-malware-sweepSource advisory - npm@coralxyz/anchor
- High8 Aug 20261 package tracked
GitHub Advisory PyPI CWE-506 sweep - 2026-08-08 batch (`riakcs` Basho Riak-CS Python client typosquat with setup.py install-time host reconnaissance)
GHSA published one PyPI CWE-506 advisory dated 2026-08-08:
riakcs(v0.0.1 and v0.5.0) - a typosquat/naming-collision on Basho Riak-CS Python client. Overridessetup.py installto silently exfiltrate the installer host IP + username at install time. OpenSSF MAL-2026-13665, discovery creditkam193.PyPIAffected packages1 package · 2 versions
- PyPIriakcs0.0.10.5.0
pypi-2026-08-08-ghsa-malware-sweepSource advisory - PyPIriakcs
- Critical7 Aug 202632 packages tracked
GitHub Advisory npm CWE-506 sweep - 33+ package 2026-08-07 batch (`remote-claude-daemon` full-desktop RAT via WebSocket relay + baileys-clone WhatsApp bot cluster + `@cats-cdf/*` OAST recon pair + `internallib_v514` internal LAN reverse-shell + `wormgpt-cli` LLM-branded RAT + `@united-airlines-org/atmos-design-system` dep-confusion + `@ks-video/kwai-player-web` telemetry beacon + `@avi892nash/aegis-grid-runner` Juspay-leaked internal RCE tool + `@junyoung-kim/reins` PTY-reverse-shell with systemd persistence + `noviembrenacional.com` WordPress-CSRF nuke pair + long tail)
GHSA published 33+ npm CWE-506 advisories dated 2026-08-07 spanning several clusters:
remote-claude-daemon(Claude Code full-desktop RAT with screen + mic capture via WebSocket relay, 20 versions), a 4-package baileys-clone WhatsApp bot cluster (@prototypevip/baileys,diezyclutch-baileys,ynastore-baileys, and more),@cats-cdf/*OAST dep-confusion recon,internallib_v514reverse-shell to hardcoded10.0.70.90(continuation ofinternallib_v<NNN>campaign),wormgpt-cli(LLM-branded RAT with clipboard theft),@united-airlines-org/atmos-design-systemdep-confusion,@ks-video/kwai-player-webtelemetry beacon,@avi892nash/aegis-grid-runner(leaked-internal-Juspay RCE tool),@junyoung-kim/reins(PTY reverse-shell with systemd persistence), andxxdxax+xdaxx(targeted WordPress CSRF/account-nuke againstnoviembrenacional.com).npmAffected packages32 packages · 73 versions
- npm@avi892nash/aegis-grid-runner0.3.00.3.10.3.20.3.3
- npm@cats-cdf/authentication2.17.13.1.1
- npm@cats-cdf/browser-metrics-meter2.0.03.1.1
- npm@junyoung-kim/reins0.1.60.1.7
- npm@ks-video/kwai-player-web9.1.09.1.19.1.2
- npm@prototypevip/baileys0.0.10.0.20.0.3
- npm@united-airlines-org/atmos-design-system40.0.040.1.041.0.0
- npmcdf-tag-commander-helper1.0.0
- npmdiezyclutch-baileys1.0.0
- npmdpdgroup-css1.0.0
- npminternallib_v5141.0.0
- npmlib-frontsga1.0.0
- npmmerge-grid-stats1.0.0
- npmrdfxvela1.0.0
- npmrdfxvela-build1.0.0
- npmremote-claude-daemon0.3.00.3.40.3.50.3.60.3.70.3.80.3.90.4.20.4.60.4.70.5.00.5.20.5.40.5.50.5.70.5.90.6.00.6.10.6.20.6.6
- npmsqueez1.0.0
- npmstreak-map-cache1.0.0
- npmstretchshop1.0.0
- npmsupersig1.0.0
- npmtrimprompt1.0.0
- npmvelabuild1.0.0
- npmvite-plugin-cleaner1.0.0
- npmvite-svg-parse1.0.0
- npmvite-vue-path-map1.0.0
- npmweight2loss1.0.0
- npmwormgpt-cli1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.8
- npmwos-library-ui1.0.0
- npmxdaxx1.0.01.0.1
- npmxxdxax1.0.01.0.1
- npmynastore-baileys1.0.0
- npmzyr-agent1.0.0
npm-2026-08-07-ghsa-malware-sweepSource advisory - npm@avi892nash/aegis-grid-runner
- Critical7 Aug 202610 packages tracked
GitHub Advisory PyPI CWE-506 sweep - 10-package 2026-08-07 batch (`2026-08-alphalend-layouts` Sui keystore-stealer pair with PTH persistence + `2026-08-flasq` typosquat wave: `pydanticc`+`flasq`+`idnna`+`fastapii`+`fast-hashes`+`speed-hashes` crypto-wallet stealers + `cdktn-provider-azurerm` cdktf HashiCorp jsii-chain typosquat + `atlas-internal` dep-confusion recon)
GHSA published 10 PyPI CWE-506 advisories dated 2026-08-07 across three clusters:
2026-08-alphalend-layoutsSui keystore-stealer pair with PTH file persistence (alphalend-layouts,alphalend-abi);2026-08-flasqtyposquat wave dropping crypto-wallet stealers (pydanticc,flasq,idnna,fastapii,fast-hashes,speed-hashes); and singletonscdktn-provider-azurerm(HashiCorp cdktf typosquat with jsii import-time chain) andatlas-internal(dep-confusion recon).PyPIAffected packages10 packages · 27 versions
- PyPIalphalend-abi1.0.01.0.11.1.0
- PyPIalphalend-layouts4.0.04.0.14.0.24.1.0
- PyPIatlas-internal1.8.1
- PyPIcdktn-provider-azurerm17.0.0
- PyPIfast-hashes0.1.0
- PyPIfastapii0.1.10.1.20.2.00.3.0
- PyPIflasq0.1.10.1.20.2.00.3.0
- PyPIidnna0.1.10.1.20.2.00.3.0
- PyPIpydanticc0.1.10.1.20.2.00.3.0
- PyPIspeed-hashes0.1.0
pypi-2026-08-07-ghsa-malware-sweepSource advisory - PyPIalphalend-abi
- Critical6 Aug 202658 packages tracked
GitHub Advisory npm CWE-506 sweep - 50+ package 2026-08-06 batch (Sui-blockchain `sui-migration-audit-*` + `move-bcs-codec` cluster, `@activepieces/piece-*` typosquat sweep, `@ccfly/setup-*` platform-binary quartet, `@addai/*` cluster, `claude-remote-agent` RAT, `diezyyasha-baileys` + `alipclutch-baileys` WhatsApp cluster, `@holocronlab/botruntime-runtime` bot-framework masquerade, `helmet-pro` + `agenttunnels` + `agenthub-multiagent-mcp` + `typst-resume-cli` misc)
GHSA published 50+ npm CWE-506 advisories dated 2026-08-06 spanning several clusters: Sui blockchain tooling (
sui-migration-audit-cli,sui-graphql-client,sui-migration-audit-rules,move-bcs-codec), an@activepieces/piece-*typosquat sweep (piece-google-contacts,piece-google-bigquery,piece-google-forms,piece-base44), a@ccfly/setup-*platform-binary quartet (darwin-arm64,darwin-x64,linux-arm64,linux-x64), an@addai/*cluster (ainode,node,entity-runtime),claude-remote-agentRAT, WhatsAppdiezyyasha-baileys+alipclutch-baileyssibling clones,@holocronlab/botruntime-runtimebot framework masquerade, and a long tail of enterprise-scope dep-confusion probes.npmAffected packages58 packages · 58 versions
- npm@0l00000l/auth1.0.0
- npm@activepieces/piece-base441.0.0
- npm@activepieces/piece-google-bigquery1.0.0
- npm@activepieces/piece-google-contacts1.0.0
- npm@activepieces/piece-google-forms1.0.0
- npm@addai/ainode1.0.0
- npm@addai/entity-runtime1.0.0
- npm@addai/node1.0.0
- npm@apicity/meta1.0.0
- npm@astralcore/aura-wb1.0.0
- npm@atom8n/inspector1.0.0
- npm@aubea/mars1.0.0
- npm@bananacool467/ui-tools1.0.0
- npm@ccfly/setup-darwin-arm641.0.0
- npm@ccfly/setup-darwin-x641.0.0
- npm@ccfly/setup-linux-arm641.0.0
- npm@ccfly/setup-linux-x641.0.0
- npm@chnayser/server1.0.0
- npm@holocronlab/botruntime-runtime1.0.0
- npm@innocarpe/deepseek-build1.0.0
- npm@leejungkiin/awkit1.0.0
- npm@love-moon/conductor-cli1.0.0
- npm@trackunit/iris-app-sdk-vite1.0.0
- npm@vanexalabs-ai/vanexa-agent1.0.0
- npm@xiaohhhh1/canvas-agent1.0.0
- npm9remote1.0.0
- npmagenthub-multiagent-mcp1.0.0
- npmagenttunnels1.0.0
- npmalipclutch-baileys1.0.0
- npmapp-api-sdk1.0.0
- npmbeautiful-ui-monitoring1.0.0
- npmbigops-tcrm-permissions1.0.0
- npmclaude-remote-agent1.0.0
- npmdevplatform-data-table1.0.0
- npmdevplatform-jscodeshift-utils1.0.0
- npmdevplatform-spa-plugin-error-boundary1.0.0
- npmdevplatform-vite-plugin-gle1.0.0
- npmdiezyyasha-baileys1.0.0
- npmezdiscordbots1.0.0
- npmfetchrtds1.0.0
- npmhelmet-pro1.0.0
- npmjagproject1.0.0
- npmmove-bcs-codec1.0.0
- npmnpm-dc-dev1.1.1
- npmstatist-browser-typed-client-sme.rko.tariffs.web1.0.0
- npmstatist-statist-core1.0.0
- npmstreak-cache-map1.0.0
- npmsui-graphql-client1.0.0
- npmsui-migration-audit-cli1.0.0
- npmsui-migration-audit-rules1.0.0
- npmsvelte-visual-map1.0.0
- npmtailwindcss-hide-scrollbar1.0.0
- npmtinkoff-boxy-desktop-two-panel-right-image1.0.0
- npmtinkoff-codeceptjs-storyshots-alpha1.0.0
- npmtsihealth-client1.0.0
- npmtui-react-tooltip1.0.0
- npmtypst-resume-cli1.0.0
- npmvitest-preview-pro-all1.0.0
npm-2026-08-06-ghsa-malware-sweepSource advisory - npm@0l00000l/auth
- Critical6 Aug 20263 packages tracked
GitHub Advisory PyPI CWE-506 sweep - 3-package 2026-08-06 batch (`xAyOuB-XcTxTeaM` Garena Free Fire spam-cannon botnet + `uncrypt` browser infostealer + `decapod-common` pentest)
GHSA published 3 PyPI CWE-506 advisories dated 2026-08-06:
xAyOuB-XcTxTeaM(Garena Free Fire spam-cannon opening a Flask server on 0.0.0.0:50019 with ~20 hardcoded account credentials for gaming-platform abuse),uncrypt(embedded-executable browser-data infostealer with sandbox detection, campaign2026-08-uncrypt), anddecapod-common(pentest host-recon underGENERIC-standard-pypi-install-pentest).PyPIAffected packages3 packages · 9 versions
- PyPIdecapod-common0.0.01.2.dev11.2.dev2
- PyPIuncrypt0.1.00.1.10.1.2
- PyPIxAyOuB-XcTxTeaM0.1.00.1.10.1.2
pypi-2026-08-06-ghsa-malware-sweepSource advisory - PyPIdecapod-common
- Critical5 Aug 202642 packages tracked
GitHub Advisory npm CWE-506 sweep - 40+ package 2026-08-05 batch (massive Tinkoff Bank / dolyame BNPL / bnpl-blocks / tramvai / statist enterprise-scope dep-confusion burst, plus `clawtrl-wallet` crypto stealer + `sextant-cli-darwin-arm64` platform-binary + `@lizhao1/memorax-code-internal` + `@cliphijack/santaclaude` Claude-themed clipboard hijack + `llm-interceptor` + `multi-acct` + `kepler`)
GHSA published 40+ npm CWE-506 advisories dated 2026-08-05 dominated by a massive Tinkoff Bank (Russian bank) enterprise-scope dep-confusion burst:
tinkoff-*,dolyame-boxy-*(Tinkoff BNPL),bnpl-blocks-atom-*,tramvai-*(Tinkoff's open-source framework),bigops-*,sme.rko.*internal namespaces. Alsoclawtrl-wallet(crypto wallet stealer),@cliphijack/santaclaude(Claude-themed clipboard hijack),sextant-cli-darwin-arm64,@lizhao1/memorax-code-internal,llm-interceptor,multi-acct,kepler,express-dever,svelte-mapped-metrics,streak-math-calc,streak-calc-metrics,svelte-mapping-core,eslint-plugin-vitest-ts,tailwindcss-scrollbar-hide,express-rate-controller,@stageflight-testbed/a,@workoscalif/sudoku,trapp-check-logs,sme-foundation-frame-manager.npmAffected packages42 packages · 42 versions
- npm@cliphijack/santaclaude1.0.0
- npm@ikbal_fadilah_vanexa01/vanexa-agent1.0.0
- npm@lizhao1/memorax-code-internal1.0.0
- npm@stageflight-testbed/a1.0.0
- npm@workoscalif/sudoku1.0.0
- npmbigops-auth1.0.0
- npmbnpl-blocks-atom-bnpl-action-card1.0.0
- npmbnpl-blocks-atom-bnpl-badge1.0.0
- npmbnpl-blocks-atom-bnpl-dolyame-button1.0.0
- npmbnpl-blocks-atom-bnpl-dropdown1.0.0
- npmbnpl-blocks-atom-bnpl-email-form1.0.0
- npmbnpl-blocks-atom-bnpl-info-card1.0.0
- npmbnpl-blocks-atom-bnpl-integrations-breadcrumbs1.0.0
- npmbnpl-blocks-atom-bnpl-news-card1.0.0
- npmclawtrl-wallet1.0.0
- npmdolyame-boxy-desktop-bnpl-text-block1.0.0
- npmdolyame-boxy-fonts1.0.0
- npmdolyame-boxy-independent-bnpl-info-slider1.0.0
- npmdolyame-boxy-independent-bnpl-items1.0.0
- npmdolyame-boxy-independent-bnpl-partners1.0.0
- npmdolyame-boxy-independent-bnpl-picture-gallery1.0.0
- npmdolyame-boxy-independent-bnpl-search1.0.0
- npmeslint-plugin-vitest-ts1.0.0
- npmexpress-dever1.0.0
- npmexpress-rate-controller1.0.0
- npmkepler1.0.0
- npmllm-interceptor1.0.0
- npmmulti-acct1.0.0
- npmsextant-cli-darwin-arm641.0.0
- npmsme-foundation-frame-manager1.0.0
- npmstreak-calc-metrics1.0.0
- npmstreak-math-calc1.0.0
- npmsvelte-mapped-metrics1.0.0
- npmsvelte-mapping-core1.0.0
- npmtailwindcss-scrollbar-hide1.0.0
- npmtinkoff-pfp-block-desktop-tabs1.0.0
- npmtinkoff-statist-browser-typed-client-itsa.candy.selfservicesupport.frontend.events1.0.0
- npmtinkoff-statist-browser-typed-client-sme.rko.origsmartphonepaytb.common.mobile.events1.0.0
- npmtinkoff-volna-zustate1.0.0
- npmtramvai-module-feature-toggle1.0.0
- npmtrapp-check-logs1.0.0
- npmvvvedernikov-test-another-test1.0.0
npm-2026-08-05-ghsa-malware-sweepSource advisory - npm@cliphijack/santaclaude
- Critical5 Aug 20264 packages tracked
GitHub Advisory PyPI CWE-506 sweep - 4-package 2026-08-05 batch (`2026-08-bip39-py` crypto-wallet infostealer campaign: `solana-sniper-bot` + `eth-account-wallet` + `mnemonic-py` + `defi-sdk-py`)
GHSA published 4 PyPI CWE-506 advisories dated 2026-08-05, all attributed to campaign
2026-08-bip39-py:solana-sniper-bot,eth-account-wallet,mnemonic-py, anddefi-sdk-py. All four use setup.py install-command override to exfiltrate env vars, browser data, crypto wallet files, SSH keys, and configuration files. Cross-chain crypto-wallet targeting (Solana + Ethereum + generic mnemonic phrases + DeFi).PyPIAffected packages4 packages · 4 versions
- PyPIdefi-sdk-py2.5.1
- PyPIeth-account-wallet0.11.2
- PyPImnemonic-py0.21
- PyPIsolana-sniper-bot1.4.2
pypi-2026-08-05-ghsa-malware-sweepSource advisory - PyPIdefi-sdk-py
- Critical4 Aug 2026443 packages tracked
keyv / cacheable family hijacked in Shai-Hulud "Here We Go Again" worm
On 2026-08-04 a compromised maintainer account pushed a
preinstallcredential stealer into thekeyv/cacheablefamily and the worm spread via stolen npm tokens across ~2B monthly installs. Releases were cut frommain, so npm signed them with valid provenance. Verified count as of the Wiz IOC feed: 443 npm packages across 2,235 versions; SafeDep's registry-backed telemetry puts the total at 1,684 versions across 420 names tied to nine orgs.npmAffected packages443 packages · 2235 versions
- npm@adminide-stack/clock-tik-browser12.0.24
- npm@adminide-stack/yantra-mobile12.0.33
- npm@arv-bedrock/auth1.1.71.1.8
- npm@arv-bedrock/auth-admin1.0.21.0.3
- npm@arv-bedrock/auth-sso1.6.11.6.2
- npm@arv-bedrock/auth-sso-backend1.7.11.7.2
- npm@arv-bedrock/logger1.7.11.7.2
- npm@cacheable/memory2.2.1
- npm@cacheable/net2.1.1
- npm@cacheable/node-cache3.1.2
- npm@cacheable/utils2.5.1
- npm@deliveroo/determinator0.2.1
- npm@deliveroo/reevent1.0.1
- npm@hubsync/web-sdk-react6.3.76.3.86.3.96.3.106.3.116.3.126.3.136.3.146.3.156.3.166.3.176.3.186.3.196.3.206.3.216.3.226.3.236.3.246.3.256.3.266.3.276.3.286.3.296.3.306.3.316.3.326.3.33
- npm@nebula.js/cli7.1.2
- npm@nebula.js/cli-build7.1.2
- npm@nebula.js/cli-sense7.1.2
- npm@nebula.js/locale0.6.2
- npm@nebula.js/nucleus0.5.1
- npm@nebula.js/sn-action-button2.3.1
- npm@nebula.js/sn-animator2.13.1
- npm@nebula.js/sn-distributionplot1.0.7
- npm@nebula.js/sn-layout-container4.4.1
- npm@nebula.js/sn-line-chart2.7.1
- npm@nebula.js/sn-listbox0.19.3
- npm@nebula.js/sn-map0.12.7
- npm@nebula.js/sn-nav-menu0.14.2
- npm@nebula.js/sn-org-chart1.7.1
- npm@nebula.js/sn-shape1.5.1
- npm@nebula.js/sn-slider0.20.1
- npm@nebula.js/sn-tabbed-container2.4.1
- npm@nebula.js/snapshooter0.6.1
- npm@nebula.js/stardust7.1.2
- npm@nebula.js/test-utils0.6.1
- npm@nebula.js/theme0.6.1
- npm@onereach/authorizer-helper0.0.110.0.120.0.13
- npm@onereach/bandwidth-steps-voice-bxml0.1.10.1.20.1.3
- npm@onereach/billing-dto27.2.127.2.227.2.3
- npm@onereach/billing-shared27.2.127.2.227.2.3
- npm@onereach/cb-schema-translator1.3.11.3.21.3.3
- npm@onereach/channel-transformer0.0.660.0.670.0.68
- npm@onereach/channel-transformers0.0.50.0.60.0.7
- npm@onereach/ckeditor5-build-classic30.0.130.0.230.0.3
- npm@onereach/condition-builder1.0.81.0.91.0.10
- npm@onereach/content-builder0.0.180.0.190.0.20
- npm@onereach/content-builder-template-compiler0.0.30.0.40.0.5
- npm@onereach/expression-components9.1.19.1.29.1.3
- npm@onereach/font-icons27.0.227.0.327.0.4
- npm@onereach/get-version-data3.1.23.1.33.1.4
- npm@onereach/idw-apps0.1.30.1.40.1.5
- npm@onereach/idw-contracts0.1.20.1.30.1.4
- npm@onereach/idw-init-account-resources1.0.11.0.21.0.3
- npm@onereach/idw-sdk0.1.20.1.30.1.4
- npm@onereach/idw-ui-components0.1.20.1.30.1.4
- npm@onereach/lambda-invocation1.2.11.2.21.2.3
- npm@onereach/messengers-infobip-sdk0.1.10.1.20.1.3
- npm@onereach/or-browser0.0.480.0.490.0.50
- npm@onereach/or-browser-next0.0.110.0.120.0.13
- npm@onereach/or-content-builder-renderer0.0.20.0.30.0.4
- npm@onereach/or-file-uploader-next0.0.80.0.90.0.10
- npm@onereach/or-pro1.13.11.13.21.13.3
- npm@onereach/or-sdk-agent-cli0.0.60.0.70.0.8
- npm@onereach/orest-cli2.4.12.4.22.4.3
- npm@onereach/orest-input-cli1.18.11.18.21.18.3
- npm@onereach/orest-jest-presets0.0.30.0.40.0.5
- npm@onereach/orest-vue-demi-vue20.0.40.0.50.0.6
- npm@onereach/orest-vue-demi-vue30.0.40.0.50.0.6
- npm@onereach/orest-vue30.0.40.0.50.0.6
- npm@onereach/phonenumber-interpreter0.0.180.0.190.0.20
- npm@onereach/pnpm-audit-junit1.0.31.0.41.0.5
- npm@onereach/postcss-scoped-selector1.2.11.2.21.2.3
- npm@onereach/regex-helper0.5.160.5.170.5.18
- npm@onereach/regular-expressions0.5.230.5.240.5.25
- npm@onereach/regular-expressions-test0.0.40.0.50.0.6
- npm@onereach/rwc-client6.4.76.4.86.4.9
- npm@onereach/salesforce-miaw-client0.0.30.0.40.0.5
- npm@onereach/si-a-button0.0.30.0.40.0.5
- npm@onereach/si-alert0.4.110.4.120.4.13
- npm@onereach/si-checkbox0.6.50.6.60.6.7
- npm@onereach/si-checkbox-group0.3.50.3.60.3.7
- npm@onereach/si-code0.6.40.6.50.6.6
- npm@onereach/si-collapsible-group0.6.40.6.50.6.6
- npm@onereach/si-copyable-text0.4.110.4.120.4.13
- npm@onereach/si-datepicker0.4.50.4.60.4.7
- npm@onereach/si-divider0.4.110.4.120.4.13
- npm@onereach/si-dropdown-advanced0.4.50.4.60.4.7
- npm@onereach/si-dropdown-simple0.4.50.4.60.4.7
- npm@onereach/si-header0.4.110.4.120.4.130.4.14
- npm@onereach/si-list0.7.40.7.50.7.6
- npm@onereach/si-merge-tag-input0.4.50.4.60.4.7
- npm@onereach/si-radio-group0.3.50.3.60.3.7
- npm@onereach/si-root0.9.40.9.50.9.6
- npm@onereach/si-select0.1.30.1.40.1.5
- npm@onereach/si-step-chooser0.4.40.4.50.4.6
- npm@onereach/si-switch0.4.50.4.60.4.7
- npm@onereach/si-text-message0.4.50.4.60.4.7
- npm@onereach/si-textinput0.5.50.5.60.5.7
- npm@onereach/si-validated-timestring-input0.3.50.3.60.3.7
- npm@onereach/slack-helpers1.0.31.0.41.0.5
- npm@onereach/ssml-editor2.0.122.0.132.0.14
- npm@onereach/step-components0.1.370.1.380.1.39
- npm@onereach/step-conversation1.0.411.0.421.0.43
- npm@onereach/step-run-snowflake-query0.1.10.1.20.1.3
- npm@onereach/step-voice7.0.327.0.337.0.34
- npm@onereach/styles27.0.227.0.327.0.4
- npm@onereach/time-interpreter1.0.301.0.311.0.32
- npm@onereach/ts-memoize1.0.21.0.31.0.4
- npm@onereach/types-contacts-api9.0.89.0.99.0.10
- npm@onereach/ui-components27.0.227.0.327.0.4
- npm@onereach/ui-components-common27.0.227.0.327.0.4
- npm@onereach/ui-components-vue227.0.227.0.327.0.4
- npm@onereach/v-event-calendar0.1.220.1.230.1.24
- npm@onereach/webform0.3.130.3.140.3.15
- npm@or-sdk/account-settings1.3.61.3.71.3.8
- npm@or-sdk/accounts2.3.52.3.62.3.7
- npm@or-sdk/adapters0.3.60.3.70.3.8
- npm@or-sdk/agents4.21.34.21.44.21.5
- npm@or-sdk/api-tokens1.4.21.4.31.4.4
- npm@or-sdk/api-tokens-lambda1.4.21.4.31.4.4
- npm@or-sdk/apps1.2.61.2.71.2.8
- npm@or-sdk/auth0.38.10.38.20.38.3
- npm@or-sdk/authorizer0.26.70.26.80.26.9
- npm@or-sdk/base0.44.40.44.50.44.6
- npm@or-sdk/billing27.2.127.2.227.2.3
- npm@or-sdk/billing-internal27.2.127.2.227.2.3
- npm@or-sdk/bot-templates2.2.52.2.62.2.7
- npm@or-sdk/bots1.7.11.7.21.7.3
- npm@or-sdk/card-templates2.2.52.2.62.2.7
- npm@or-sdk/cards1.2.51.2.61.2.7
- npm@or-sdk/ccp10.15.410.15.510.15.6
- npm@or-sdk/chat0.3.10.3.20.3.3
- npm@or-sdk/contacts4.7.54.7.64.7.7
- npm@or-sdk/content-request0.2.60.2.70.2.8
- npm@or-sdk/data-hub0.26.50.26.60.26.7
- npm@or-sdk/data-hub-svc2.3.52.3.62.3.7
- npm@or-sdk/deployer1.7.51.7.61.7.7
- npm@or-sdk/deployments2.1.52.1.62.1.7
- npm@or-sdk/discovery1.12.11.12.21.12.3
- npm@or-sdk/druid1.4.71.4.81.4.9
- npm@or-sdk/event-manager1.1.51.1.61.1.7
- npm@or-sdk/files3.11.63.11.73.11.8
- npm@or-sdk/files-sync-node0.1.80.1.90.1.10
- npm@or-sdk/flow-templates2.1.52.1.62.1.7
- npm@or-sdk/flows2.7.82.7.92.7.10
- npm@or-sdk/graph1.10.51.10.61.10.7
- npm@or-sdk/hitl0.41.10.41.20.41.3
- npm@or-sdk/identifiers0.27.60.27.70.27.8
- npm@or-sdk/idw9.0.49.0.59.0.6
- npm@or-sdk/idw-public1.6.61.6.71.6.8
- npm@or-sdk/idw-skill1.4.11.4.21.4.3
- npm@or-sdk/invitations1.4.81.4.91.4.10
- npm@or-sdk/key-value-storage0.28.60.28.70.28.8
- npm@or-sdk/keys1.2.61.2.71.2.8
- npm@or-sdk/knowledge-models0.25.50.25.60.25.7
- npm@or-sdk/library0.5.60.5.70.5.8
- npm@or-sdk/library-categories0.2.60.2.70.2.8
- npm@or-sdk/library-source0.4.50.4.60.4.7
- npm@or-sdk/library-types-v19.0.19.0.29.0.3
- npm@or-sdk/library-types-v29.0.19.0.29.0.3
- npm@or-sdk/lookup1.25.11.25.21.25.3
- npm@or-sdk/markdowner0.5.10.5.20.5.3
- npm@or-sdk/mcp-tools0.5.20.5.30.5.4
- npm@or-sdk/notifications1.7.51.7.61.7.7
- npm@or-sdk/password1.3.61.3.71.3.8
- npm@or-sdk/payments3.2.53.2.63.2.7
- npm@or-sdk/permissions2.8.12.8.22.8.3
- npm@or-sdk/permissions-cli1.4.11.4.21.4.3
- npm@or-sdk/permissions-lambda2.5.12.5.22.5.3
- npm@or-sdk/pgsql1.5.11.5.21.5.3
- npm@or-sdk/providers0.3.60.3.70.3.8
- npm@or-sdk/qna3.4.23.4.33.4.4
- npm@or-sdk/queue-manager1.4.61.4.71.4.8
- npm@or-sdk/sdk-api0.29.20.29.30.29.4
- npm@or-sdk/settings0.25.60.25.70.25.8
- npm@or-sdk/sku-builder2.5.12.5.22.5.3
- npm@or-sdk/source2.1.52.1.62.1.7
- npm@or-sdk/source-api1.1.11.1.21.1.3
- npm@or-sdk/step-templates2.2.52.2.62.2.7
- npm@or-sdk/store2.1.52.1.62.1.7
- npm@or-sdk/tables0.28.50.28.60.28.7
- npm@or-sdk/tags1.1.51.1.61.1.7
- npm@or-sdk/tickets1.9.51.9.61.9.7
- npm@or-sdk/transcripts1.2.51.2.61.2.7
- npm@or-sdk/users3.8.13.8.23.8.3
- npm@or-sdk/view-templates2.2.52.2.62.2.7
- npm@or-sdk/views3.1.53.1.63.1.7
- npm@or-sdk/web-search0.6.10.6.20.6.3
- npm@ornikar/apollo-link-timeout1.4.21.4.31.4.41.4.51.4.61.4.71.4.81.4.91.4.101.4.11
- npm@ornikar/babel-preset-base6.0.36.0.46.0.56.0.66.0.76.0.86.0.96.0.106.0.116.0.126.0.136.0.14
- npm@ornikar/babel-preset-kitt-universal8.0.38.0.48.0.58.0.68.0.78.0.88.0.98.0.108.0.118.0.12
- npm@ornikar/babel-preset-react6.1.46.1.56.1.66.1.76.1.86.1.96.1.106.1.116.1.126.1.136.1.14
- npm@ornikar/browserslist-config8.0.38.0.48.0.58.0.68.0.78.0.88.0.98.0.108.0.11
- npm@ornikar/commitlint-config8.3.28.3.38.3.48.3.58.3.68.3.78.3.88.3.98.3.108.3.118.3.12
- npm@ornikar/eslint-config24.0.124.0.224.0.324.0.424.0.524.0.624.0.724.0.824.0.924.0.1024.0.1124.0.12
- npm@ornikar/eslint-config-babel24.0.124.0.224.0.324.0.424.0.524.0.624.0.724.0.824.0.924.0.1024.0.1124.0.12
- npm@ornikar/eslint-config-babel-use13.2.113.2.213.2.313.2.413.2.513.2.613.2.713.2.813.2.913.2.1013.2.1113.2.12
- npm@ornikar/eslint-config-formatjs24.0.124.0.224.0.324.0.424.0.524.0.624.0.724.0.824.0.924.0.10
- npm@ornikar/eslint-config-node12.2.112.2.212.2.312.2.412.2.512.2.612.2.712.2.812.2.912.2.10
- npm@ornikar/eslint-config-react24.0.124.0.224.0.324.0.424.0.524.0.624.0.724.0.824.0.924.0.1024.0.11
- npm@ornikar/eslint-config-typescript24.0.124.0.224.0.324.0.424.0.524.0.624.0.724.0.824.0.924.0.10
- npm@ornikar/eslint-config-typescript-nestjs24.0.124.0.224.0.324.0.424.0.524.0.624.0.724.0.824.0.924.0.1024.0.11
- npm@ornikar/eslint-config-typescript-react24.0.124.0.224.0.324.0.424.0.524.0.624.0.724.0.824.0.924.0.1024.0.11
- npm@ornikar/eslint-plugin-neverthrow1.3.11.3.21.3.31.3.41.3.51.3.61.3.71.3.81.3.91.3.101.3.111.3.12
- npm@ornikar/eslint-plugin-ornikar24.0.124.0.224.0.324.0.424.0.524.0.624.0.724.0.824.0.924.0.1024.0.11
- npm@ornikar/graphql-config1.1.11.1.21.1.31.1.41.1.51.1.61.1.71.1.81.1.91.1.101.1.11
- npm@ornikar/intl-config10.0.210.0.310.0.410.0.510.0.610.0.710.0.810.0.910.0.10
- npm@ornikar/jest-config13.0.313.0.413.0.513.0.613.0.713.0.813.0.913.0.1013.0.1113.0.1213.0.13
- npm@ornikar/jest-config-react18.0.218.0.318.0.418.0.518.0.618.0.718.0.818.0.918.0.1018.0.11
- npm@ornikar/jest-config-react-native17.0.217.0.317.0.417.0.517.0.617.0.717.0.817.0.917.0.1017.0.1117.0.12
- npm@ornikar/jest-config-react-native-web12.0.312.0.412.0.512.0.612.0.712.0.812.0.912.0.1012.0.1112.0.1212.0.13
- npm@ornikar/kitt21.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.11
- npm@ornikar/lerna-config11.0.111.0.211.0.311.0.411.0.511.0.611.0.711.0.811.0.911.0.1011.0.11
- npm@ornikar/monorepo-config14.3.214.3.314.3.414.3.514.3.614.3.714.3.814.3.914.3.1014.3.1114.3.1214.3.13
- npm@ornikar/postcss-config9.1.29.1.39.1.49.1.59.1.69.1.79.1.89.1.99.1.109.1.119.1.12
- npm@ornikar/prettier-config9.0.39.0.49.0.59.0.69.0.79.0.89.0.99.0.109.0.11
- npm@ornikar/prismic-components0.0.20.0.30.0.40.0.50.0.60.0.70.0.80.0.90.0.100.0.110.0.12
- npm@ornikar/react-modern-calendar-datepicker3.2.13.2.23.2.33.2.43.2.53.2.63.2.73.2.83.2.93.2.103.2.11
- npm@ornikar/react-native-svg-transformer1.0.61.0.71.0.81.0.91.0.101.0.111.0.121.0.13
- npm@ornikar/renovate-config9.0.29.0.39.0.49.0.59.0.69.0.79.0.89.0.99.0.109.0.119.0.129.0.13
- npm@ornikar/repo-config15.3.315.3.415.3.515.3.615.3.715.3.815.3.915.3.1015.3.1115.3.1215.3.13
- npm@ornikar/repo-config-react13.0.813.0.913.0.1013.0.1113.0.1213.0.1313.0.1413.0.1513.0.1613.0.1713.0.1813.0.19
- npm@ornikar/repo-config-react-legacy-css15.1.215.1.315.1.415.1.515.1.615.1.715.1.815.1.915.1.1015.1.1115.1.1215.1.13
- npm@ornikar/rollup-config11.1.211.1.311.1.411.1.511.1.611.1.711.1.811.1.911.1.1011.1.1111.1.1211.1.13
- npm@ornikar/rollup-plugin-postcss2.0.52.0.62.0.72.0.82.0.92.0.102.0.112.0.122.0.132.0.142.0.15
- npm@ornikar/slate-react-fork1.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.11
- npm@ornikar/storybook-config12.1.212.1.312.1.412.1.512.1.612.1.712.1.812.1.912.1.10
- npm@ornikar/stylelint-config14.0.314.0.414.0.514.0.614.0.714.0.814.0.914.0.1014.0.1114.0.1214.0.13
- npm@ornikar/typed-css-modules-loader0.8.20.8.30.8.40.8.50.8.60.8.70.8.80.8.90.8.100.8.110.8.12
- npm@ornikar/webpack-config12.0.212.0.312.0.412.0.512.0.612.0.712.0.812.0.912.0.1012.0.1112.0.12
- npm@picsart/ai-sdk3.32.2
- npm@picsart/gen-ai2.55.11
- npm@qlik/api2.14.2
- npm@qlik/browserslist-config3.0.2
- npm@qlik/carbon-core2.1.1
- npm@qlik/carboncopy1.1.6
- npm@qlik/design-tokens1.3.13
- npm@qlik/dts-bundler2.0.3
- npm@qlik/embed-react2.5.3
- npm@qlik/embed-runtime1.6.4
- npm@qlik/embed-svelte1.1.4
- npm@qlik/embed-web-components1.7.3
- npm@qlik/eslint-config2.0.20
- npm@qlik/eslint-config-base0.1.1
- npm@qlik/eslint-config-react0.1.1
- npm@qlik/eslint-config-svelte0.1.1
- npm@qlik/eslint-config-vue0.1.1
- npm@qlik/nebula-table-utils2.6.9
- npm@qlik/oxfmt-config0.1.6
- npm@qlik/oxlint-config0.7.2
- npm@qlik/prettier-config1.0.3
- npm@qlik/react-native-simple-grid1.5.5
- npm@qlik/runtime-module-loader1.5.1
- npm@qlik/sdk0.28.1
- npm@qlik/sprout-design-docs1.0.2
- npm@qlik/sprout-gesture0.0.13
- npm@qlik/sprout-icons0.12.3
- npm@qlik/sprout-react6.45.3
- npm@qlik/sprout-react-table0.16.7
- npm@qlik/tsconfig1.0.3
- npm@servicetitan/acquisition-functions5.22.15.22.25.22.35.22.45.22.55.22.65.22.7
- npm@servicetitan/admin-layout2.4.32.4.42.4.52.4.62.4.72.4.82.4.9
- npm@servicetitan/admin-sql-table1.0.141.0.151.0.161.0.171.0.181.0.191.0.20
- npm@servicetitan/ajax-handlers38.1.138.1.238.1.338.1.438.1.538.1.638.1.7
- npm@servicetitan/anvil-css-utilities14.5.414.5.514.5.614.5.714.5.814.5.914.5.10
- npm@servicetitan/anvil-fonts14.5.414.5.514.5.614.5.714.5.814.5.914.5.10
- npm@servicetitan/anvil-icon0.5.10.5.20.5.30.5.40.5.50.5.60.5.7
- npm@servicetitan/anvil-icons14.5.414.5.514.5.614.5.714.5.814.5.914.5.10
- npm@servicetitan/anvil-react0.11.30.11.40.11.50.11.60.11.70.11.80.11.9
- npm@servicetitan/anvil-themes14.5.414.5.514.5.614.5.714.5.814.5.914.5.10
- npm@servicetitan/anvil-token0.4.10.4.20.4.30.4.40.4.50.4.60.4.7
- npm@servicetitan/anvil23.9.13.9.23.9.33.9.43.9.53.9.63.9.7
- npm@servicetitan/anvil2-codemods0.11.20.11.30.11.40.11.50.11.60.11.70.11.8
- npm@servicetitan/anvil2-ext-atlas4.0.24.0.34.0.44.0.54.0.64.0.74.0.8
- npm@servicetitan/anvil2-ext-charts0.2.40.2.50.2.60.2.70.2.80.2.90.2.10
- npm@servicetitan/anvil2-ext-common0.7.10.7.20.7.30.7.40.7.50.7.60.7.7
- npm@servicetitan/anvil2-ext-mwv0.0.50.0.60.0.70.0.80.0.90.0.100.0.11
- npm@servicetitan/anvil2-illustrations1.0.21.0.31.0.41.0.51.0.61.0.71.0.8
- npm@servicetitan/anvil2-mcp0.0.90.0.100.0.110.0.120.0.130.0.140.0.15
- npm@servicetitan/assist-ui2.1.12.1.22.1.32.1.42.1.52.1.62.1.7
- npm@servicetitan/assist-utils1.1.21.1.31.1.41.1.51.1.61.1.71.1.8
- npm@servicetitan/carto-charts-core0.0.20.0.30.0.40.0.50.0.60.0.70.0.8
- npm@servicetitan/carto-charts-react0.0.20.0.30.0.40.0.50.0.60.0.70.0.8
- npm@servicetitan/carto-charts-rn0.0.20.0.30.0.40.0.50.0.60.0.70.0.8
- npm@servicetitan/carto-react-kit0.8.40.8.50.8.60.8.70.8.80.8.90.8.10
- npm@servicetitan/carto-rn-kit0.0.100.0.110.0.120.0.130.0.140.0.150.0.16
- npm@servicetitan/carto-tokens0.3.10.3.20.3.30.3.40.3.50.3.60.3.7
- npm@servicetitan/component-usage28.5.128.5.228.5.328.5.428.5.528.5.628.5.7
- npm@servicetitan/confirm41.3.141.3.241.3.341.3.441.3.541.3.641.3.7
- npm@servicetitan/confirm-navigation41.3.141.3.241.3.341.3.441.3.541.3.641.3.7
- npm@servicetitan/contentful0.0.30.0.40.0.50.0.60.0.70.0.80.0.9
- npm@servicetitan/contentful-proxy1.1.121.1.131.1.141.1.151.1.161.1.171.1.18
- npm@servicetitan/cp-api1.115.11.115.21.115.31.115.41.115.51.115.61.115.7
- npm@servicetitan/cp-mfe1.115.11.115.21.115.31.115.41.115.51.115.61.115.7
- npm@servicetitan/cp-mfe-dev1.115.11.115.21.115.31.115.41.115.51.115.61.115.7
- npm@servicetitan/cp-react-hooks1.115.11.115.21.115.31.115.41.115.51.115.61.115.7
- npm@servicetitan/cp-ui1.115.11.115.21.115.31.115.41.115.51.115.61.115.7
- npm@servicetitan/culture41.3.141.3.241.3.341.3.441.3.541.3.641.3.7
- npm@servicetitan/data-query41.3.141.3.241.3.341.3.441.3.541.3.641.3.7
- npm@servicetitan/datadog-rum38.1.138.1.238.1.338.1.438.1.538.1.638.1.7
- npm@servicetitan/datetime-utils41.3.141.3.241.3.341.3.441.3.541.3.641.3.7
- npm@servicetitan/design-system14.5.414.5.514.5.614.5.714.5.814.5.914.5.10
- npm@servicetitan/docs-anvil-uikit-contrib41.3.141.3.241.3.341.3.441.3.541.3.641.3.7
- npm@servicetitan/docs-uikit38.1.138.1.238.1.338.1.438.1.538.1.638.1.7
- npm@servicetitan/document-title2.4.12.4.22.4.32.4.42.4.52.4.62.4.7
- npm@servicetitan/dte-pdf-editor1.76.11.76.21.76.31.76.41.76.51.76.61.76.7
- npm@servicetitan/dte-unlayer0.150.10.150.20.150.30.150.40.150.50.150.60.150.7
- npm@servicetitan/eh-module-communication0.2.10.2.20.2.30.2.40.2.50.2.60.2.7
- npm@servicetitan/error-boundary38.1.138.1.238.1.338.1.438.1.538.1.638.1.7
- npm@servicetitan/eslint-config38.1.138.1.238.1.338.1.438.1.538.1.638.1.7
- npm@servicetitan/eslint-plugin38.1.138.1.238.1.338.1.438.1.538.1.638.1.7
- npm@servicetitan/eslint-plugin-decorators-declare12.8.1512.8.1612.8.1712.8.1812.8.1912.8.2012.8.21
- npm@servicetitan/eslint-plugin-folder-schema38.1.138.1.238.1.338.1.438.1.538.1.638.1.7
- npm@servicetitan/eslint-plugin-mobx-612.8.1512.8.1612.8.1712.8.1812.8.1912.8.20
- npm@servicetitan/eslint-plugin-processors-stub12.8.1512.8.1612.8.1712.8.1812.8.1912.8.2012.8.21
- npm@servicetitan/examples1.2.51.2.61.2.71.2.81.2.91.2.101.2.11
- npm@servicetitan/feature-spotlight3.9.13.9.23.9.33.9.43.9.53.9.63.9.7
- npm@servicetitan/folder-lint38.1.138.1.238.1.338.1.438.1.538.1.638.1.7
- npm@servicetitan/forge0.5.10.5.20.5.30.5.40.5.50.5.60.5.7
- npm@servicetitan/form41.3.141.3.241.3.341.3.441.3.541.3.641.3.7
- npm@servicetitan/form-state41.3.141.3.241.3.341.3.441.3.541.3.641.3.7
- npm@servicetitan/grid0.0.630.0.640.0.650.0.660.0.670.0.680.0.69
- npm@servicetitan/hammer-icon1.2.11.2.21.2.31.2.41.2.51.2.61.2.7
- npm@servicetitan/hammer-react1.42.21.42.31.42.41.42.51.42.61.42.71.42.8
- npm@servicetitan/hammer-token3.1.13.1.23.1.33.1.43.1.53.1.63.1.7
- npm@servicetitan/hash-browser-router38.1.138.1.238.1.338.1.438.1.538.1.638.1.7
- npm@servicetitan/help-center1.0.81.0.91.0.101.0.111.0.121.0.131.0.14
- npm@servicetitan/html-sketchapp4.2.84.2.94.2.104.2.114.2.124.2.134.2.14
- npm@servicetitan/install38.1.138.1.238.1.338.1.438.1.538.1.638.1.7
- npm@servicetitan/intl7.2.17.2.27.2.37.2.47.2.57.2.67.2.7
- npm@servicetitan/json-render-react0.4.60.4.70.4.80.4.90.4.100.4.110.4.12
- npm@servicetitan/kendo-theme0.0.270.0.280.0.290.0.300.0.310.0.320.0.33
- npm@servicetitan/ko-bridge38.1.138.1.238.1.338.1.438.1.538.1.638.1.7
- npm@servicetitan/launchdarkly-service38.1.138.1.238.1.338.1.438.1.538.1.638.1.7
- npm@servicetitan/lazy-module38.1.138.1.238.1.338.1.438.1.538.1.638.1.7
- npm@servicetitan/ld-type-generator0.2.10.2.20.2.30.2.40.2.50.2.60.2.7
- npm@servicetitan/line-item-editor1.5.11.5.21.5.31.5.41.5.51.5.61.5.7
- npm@servicetitan/link-item41.3.141.3.241.3.341.3.441.3.541.3.641.3.7
- npm@servicetitan/log-service38.1.138.1.238.1.338.1.438.1.538.1.638.1.7
- npm@servicetitan/marketing-direct-mail-components20.1.120.1.220.1.320.1.420.1.520.1.620.1.7
- npm@servicetitan/marketing-email-components20.2.320.2.420.2.520.2.620.2.720.2.820.2.9
- npm@servicetitan/marketing-form0.1.20.1.30.1.40.1.50.1.60.1.70.1.8
- npm@servicetitan/marketing-global-route1.14.11.14.21.14.31.14.41.14.51.14.61.14.7
- npm@servicetitan/marketing-integration-widgets1.0.401.0.411.0.421.0.431.0.441.0.451.0.46
- npm@servicetitan/marketing-route1.2.11.2.21.2.31.2.41.2.51.2.61.2.7
- npm@servicetitan/marketing-ui9.3.19.3.29.3.39.3.49.3.59.3.69.3.7
- npm@servicetitan/marketing-widgets1.0.11.0.21.0.31.0.41.0.51.0.61.0.7
- npm@servicetitan/measure-sheet-data2.6.12.6.22.6.32.6.42.6.52.6.62.6.7
- npm@servicetitan/mfe-quick-actions0.5.490.5.500.5.510.5.520.5.530.5.540.5.55
- npm@servicetitan/micro-frontend0.0.40.0.50.0.60.0.70.0.80.0.90.0.10
- npm@servicetitan/microfront0.0.20.0.30.0.40.0.50.0.60.0.70.0.8
- npm@servicetitan/microfront-auth0.0.50.0.60.0.70.0.80.0.90.0.100.0.11
- npm@servicetitan/microfront-tests0.0.110.0.120.0.130.0.140.0.150.0.160.0.17
- npm@servicetitan/microfront-utils1.4.11.4.21.4.31.4.41.4.51.4.61.4.7
- npm@servicetitan/modularpayments-webfields1.0.531.0.541.0.551.0.561.0.571.0.581.0.59
- npm@servicetitan/moneyout-api-client1.29.11.29.21.29.31.29.41.29.51.29.61.29.7
- npm@servicetitan/mpa-components2.5.12.5.22.5.32.5.42.5.52.5.62.5.7
- npm@servicetitan/navigation14.1.114.1.214.1.314.1.414.1.514.1.614.1.7
- npm@servicetitan/notifications41.3.141.3.241.3.341.3.441.3.541.3.641.3.7
- npm@servicetitan/onboarding-ui18.5.118.5.218.5.318.5.418.5.518.5.618.5.7
- npm@servicetitan/quick-actions1.15.21.15.31.15.41.15.51.15.61.15.71.15.8
- npm@servicetitan/react-hooks7.7.17.7.27.7.37.7.47.7.57.7.67.7.7
- npm@servicetitan/react-ioc38.1.138.1.238.1.338.1.438.1.538.1.638.1.7
- npm@servicetitan/responsive6.1.16.1.26.1.36.1.46.1.56.1.66.1.7
- npm@servicetitan/restrict-imports38.1.138.1.238.1.338.1.438.1.538.1.638.1.7
- npm@servicetitan/schema-comparison0.1.30.1.40.1.50.1.60.1.70.1.80.1.9
- npm@servicetitan/skeleton9.2.49.2.59.2.69.2.79.2.89.2.99.2.10
- npm@servicetitan/standalone-core-feature-gates1.11.41.11.51.11.61.11.71.11.81.11.91.11.10
- npm@servicetitan/standalone-feature-flags2.3.22.3.32.3.42.3.52.3.62.3.72.3.8
- npm@servicetitan/standalone-root1.11.31.11.41.11.51.11.61.11.71.11.81.11.9
- npm@servicetitan/standalone-tm-api1.1.11.1.21.1.31.1.41.1.51.1.61.1.7
- npm@servicetitan/standalone-ui2.2.42.2.52.2.62.2.72.2.82.2.92.2.10
- npm@servicetitan/startup38.1.138.1.238.1.338.1.438.1.538.1.638.1.7
- npm@servicetitan/startup-jest2.2.12.2.22.2.32.2.42.2.52.2.62.2.7
- npm@servicetitan/startup-mfe-compat0.5.10.5.20.5.30.5.40.5.50.5.60.5.7
- npm@servicetitan/startup-utils38.1.138.1.238.1.338.1.438.1.538.1.638.1.7
- npm@servicetitan/stylelint-config38.1.138.1.238.1.338.1.438.1.538.1.638.1.7
- npm@servicetitan/suppress-warnings38.1.138.1.238.1.338.1.438.1.538.1.638.1.7
- npm@servicetitan/table41.3.141.3.241.3.341.3.441.3.541.3.641.3.7
- npm@servicetitan/tanstack-query-mobx6.2.16.2.26.2.36.2.46.2.56.2.66.2.7
- npm@servicetitan/temporal-lite3.4.13.4.23.4.33.4.43.4.53.4.63.4.7
- npm@servicetitan/testing-library6.6.16.6.26.6.36.6.46.6.56.6.66.6.7
- npm@servicetitan/thoughtspot-theme1.7.11.7.21.7.31.7.41.7.51.7.61.7.7
- npm@servicetitan/time-zones3.8.13.8.23.8.33.8.43.8.53.8.63.8.7
- npm@servicetitan/titan-chat-ui7.1.37.1.47.1.57.1.67.1.77.1.87.1.9
- npm@servicetitan/titan-chat-ui-anvil29.0.19.0.29.0.39.0.49.0.59.0.69.0.7
- npm@servicetitan/titan-chat-ui-common9.0.19.0.29.0.39.0.49.0.59.0.69.0.7
- npm@servicetitan/titan-chat-ui-cypress2.1.32.1.42.1.52.1.62.1.72.1.82.1.9
- npm@servicetitan/titan-chatbot-api9.0.19.0.29.0.39.0.49.0.59.0.69.0.7
- npm@servicetitan/titan-chatbot-client2.1.32.1.42.1.52.1.62.1.72.1.82.1.9
- npm@servicetitan/titan-chatbot-ui7.1.37.1.47.1.57.1.67.1.77.1.87.1.9
- npm@servicetitan/titan-chatbot-ui-anvil29.0.19.0.29.0.39.0.49.0.59.0.69.0.7
- npm@servicetitan/titan-chatbot-ui-cypress9.0.19.0.29.0.39.0.49.0.59.0.69.0.7
- npm@servicetitan/tokens12.9.112.9.212.9.312.9.412.9.512.9.612.9.7
- npm@servicetitan/toolbelt-shared-registry1.14.11.14.21.14.31.14.41.14.51.14.61.14.7
- npm@servicetitan/uikit-docs22.11.122.11.222.11.322.11.422.11.522.11.622.11.7
- npm@servicetitan/unit-tests0.0.20.0.30.0.40.0.50.0.60.0.70.0.8
- npm@servicetitan/va-mfe-loader1.1.11.1.21.1.31.1.41.1.51.1.61.1.7
- npm@servicetitan/web-components38.1.138.1.238.1.338.1.438.1.538.1.638.1.7
- npm@servicetitan/widget-platform5.6.15.6.25.6.35.6.45.6.55.6.65.6.7
- npm@servicetitan/widget-platform-monolith5.6.15.6.25.6.35.6.45.6.55.6.65.6.7
- npm@thiennq/docs-viewer1.6.21.6.31.6.4
- npm@umacloud/cli-darwin-arm641.0.74
- npm@umacloud/cli-darwin-x641.0.74
- npm@umacloud/cli-linux-arm641.0.74
- npm@umacloud/cli-linux-musl-arm641.0.74
- npm@umacloud/cli-linux-musl-x641.0.74
- npm@umacloud/cli-linux-x641.0.74
- npm@umacloud/cli-win32-x641.0.74
- npm@umacloud/knowledge1.0.74
- npm@workbench-stack/core3.9.8
- npmbabel-plugin-linaria-css-to-undefined0.3.10.3.20.3.30.3.40.3.50.3.60.3.70.3.80.3.90.3.100.3.110.3.120.3.130.3.140.3.150.3.160.3.17
- npmcache-manager7.2.10
- npmcacheable2.5.1
- npmcacheable-request13.0.20
- npmconv-context-next1.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.10
- npmecto5.0.1
- npmeditable-contracts0.0.120.0.130.0.140.0.150.0.160.0.170.0.180.0.190.0.200.0.210.0.220.0.230.0.240.0.250.0.260.0.27
- npmeslint-plugin-folder-schema1.0.61.0.71.0.81.0.91.0.101.0.111.0.121.0.131.0.141.0.151.0.161.0.171.0.181.0.191.0.201.0.21
- npmexample-js-project1.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.11
- npmfile-entry-cache11.1.6
- npmflat-cache6.1.24
- npmfolder-lint1.0.61.0.71.0.81.0.91.0.101.0.111.0.121.0.131.0.141.0.151.0.161.0.171.0.181.0.191.0.201.0.21
- npmfrontend-orb4.4.14.4.24.4.34.4.44.4.54.4.64.4.74.4.84.4.94.4.104.4.114.4.124.4.134.4.144.4.154.4.164.4.174.4.18
- npmhamus.js0.4.1
- npmhttp-metrics-middleware2.2.2
- npmkeyv6.0.0
- npmnative-frontend-orb1.1.41.1.51.1.61.1.71.1.81.1.91.1.101.1.111.1.121.1.131.1.141.1.151.1.161.1.171.1.181.1.19
- npmpicasso-plugin-hammer2.11.6
- npmpicasso-plugin-q2.11.6
- npmpicasso.js2.11.6
- npmpob-test-package-in-monorepo5.2.15.2.25.2.35.2.45.2.55.2.65.2.75.2.85.2.95.2.105.2.115.2.125.2.135.2.145.2.155.2.16
- npmpob-test-typescript-package-in-monorepo4.2.14.2.24.2.34.2.44.2.54.2.64.2.74.2.84.2.94.2.104.2.114.2.124.2.134.2.144.2.154.2.164.2.17
- npmqlik-chart-modules1.1.1
- npmqlik-modifiers0.10.1
- npmqlik-object-conversion0.17.2
- npmrwc-client0.29.100.29.110.29.120.29.130.29.140.29.150.29.160.29.170.29.180.29.19
- npmserver-hemera-mongo0.0.12
- npmsn-listbox0.3.3
- npmtslint-folder-schema1.0.61.0.71.0.81.0.91.0.101.0.111.0.121.0.131.0.141.0.151.0.161.0.171.0.181.0.191.0.201.0.21
- npmumadev1.0.74
- npmverdaccio-okta-oauth38.1.138.1.238.1.338.1.438.1.538.1.638.1.738.1.838.1.938.1.1038.1.1138.1.1238.1.1338.1.1438.1.1538.1.16
- npmverdaccio-tarball-local-storage38.1.138.1.238.1.338.1.438.1.538.1.638.1.738.1.838.1.938.1.1038.1.1138.1.1238.1.1338.1.1438.1.1538.1.16
- npmworkbench-browser-server0.0.2
npm-2026-08-04-shai-hulud-keyv-cacheableSource advisory - npm@adminide-stack/clock-tik-browser
- Critical4 Aug 20261 package tracked
GitHub Advisory npm CWE-506 sweep - 1-package 2026-08-04 batch (`internallib_v688` third-day continuation of the `internallib_v<NNN>` sequential dep-confusion enumeration campaign)
GHSA published 1 npm CWE-506 advisory dated 2026-08-04:
internallib_v688(>= 0) - a third-day continuation of theinternallib_v<NNN>sequential dep-confusion enumeration campaign that droppedinternallib_v524andinternallib_v568on 2026-08-03. Theinternallib_prefix explicitly probes for internal-package name collisions on any org that publishesinternallib_*internal libraries.npmAffected packages1 package · 1 version
- npminternallib_v6881.0.0
npm-2026-08-04-ghsa-malware-sweepSource advisory - npminternallib_v688
- Critical4 Aug 20264 packages tracked
GitHub Advisory PyPI CWE-506 sweep - 4-package 2026-08-04 batch (Bitcoin hardware-wallet infostealer cluster `2026-08-coldcard-helpers` + `2026-08-psbt-utils`, plus 1 pentest kit)
GHSA published 4 PyPI CWE-506 advisories dated 2026-08-04: three Bitcoin hardware-wallet infostealers -
coldcard-helpers,psbt-helpers,psbt-utils(Coldcard + PSBT Partially Signed Bitcoin Transaction targeting under campaigns2026-08-coldcard-helpers/2026-08-psbt-utils) - and a fourth pentest-flagged host-recon kitlaunchdarkly-ai-server-sdk.PyPIAffected packages4 packages · 15 versions
- PyPIcoldcard-helpers1.4.2
- PyPIlaunchdarkly-ai-server-sdk1.0.11.0.21.1.01.2.01.3.01.4.01.5.01.6.01.7.01.8.01.9.01.9.9
- PyPIpsbt-helpers1.0.0
- PyPIpsbt-utils1.0.0
pypi-2026-08-04-ghsa-malware-sweepSource advisory - PyPIcoldcard-helpers
- Critical3 Aug 202617 packages tracked
GitHub Advisory npm CWE-506 sweep - 18-package 2026-08-03 batch (`@types-beta/sdk@0.1.0-0.1.3` `@types`-namespace impersonation with Windows `nanocache.exe` WinHTTP-WebSocket RAT, 5-package `beaver-ui-*` component-library burst, `internallib_v524`/`v568` sequential dep-confusion continuation, `simple-date-formatter-new-1`/`-util-5` OpenSSF-PA C2 + command-execution pair, `tailwind-anim` Tailwind-ecosystem typosquat second-day companion, `@custombots/custombot@1.0.0` OpenSSF-PA malicious-command scoped RAT, and 5-package internal-tooling dep-confusion singleton burst)
GHSA published 18 npm CWE-506 advisories dated 2026-08-03. Most severe:
@types-beta/sdk@0.1.0-0.1.3- a@types-namespace impersonation embedding a Windowsnanocache.exeWinHTTP WebSocket RAT. Batch also includes a 5-packagebeaver-ui-*dep-confusion burst,internallib_v524/v568continuation,simple-date-formatter-*OpenSSF-PA C2+cmd pair,tailwind-anim, and 5 more.npmAffected packages17 packages · 20 versions
- npm@custombots/custombot1.0.0
- npm@types-beta/sdk0.1.00.1.10.1.20.1.3
- npmaccounts-final-form1.0.0
- npmaccounts-loading-state1.0.0
- npmbeaver-ui-date-range-picker1.0.0
- npmbeaver-ui-grid1.0.0
- npmbeaver-ui-header1.0.0
- npmbeaver-ui-items-with-more1.0.0
- npmbeaver-ui-layout1.0.0
- npmbigops-chat-messages1.0.0
- npmfluid-type-ui1.0.0
- npminternallib_v5241.0.0
- npminternallib_v5681.0.0
- npmlifestyle-test-utils1.0.0
- npmsimple-date-formatter-new-11.0.0
- npmsimple-date-formatter-util-51.0.0
- npmtailwind-anim1.0.0
npm-2026-08-03-ghsa-malware-sweepSource advisory - npm@custombots/custombot
- Critical3 Aug 20261 package tracked
GitHub Advisory PyPI CWE-506 sweep - 1-package 2026-08-03 batch (`instalogin1234@0.0.1` Instagram credential-harvester with Discord exfil, campaign `2026-08-instalogin1234`)
GHSA published 1 PyPI CWE-506 advisory dated 2026-08-03:
instalogin1234@0.0.1- masquerades as an Instagram CLI tool, captures user login credentials, exfiltrates them to a Discord channel, and opens the legitimate Instagram website in the browser to hide the theft. Attributed to campaign2026-08-instalogin1234in the OpenSSF malicious-packages repository.PyPIAffected packages1 package · 1 version
- PyPIinstalogin12340.0.1
pypi-2026-08-03-ghsa-malware-sweepSource advisory - PyPIinstalogin1234
- Critical2 Aug 20268 packages tracked
GitHub Advisory npm CWE-506 sweep - 8-package 2026-08-02 batch (`houzidawang806/807/808` sequential-namespace trio, `simple-date-formatter-util`/`-1`/`-2` date-util trio, `tailwindcss-anim` Tailwind-ecosystem typosquat, `list-issue-predecessor-dependencies-block@99.0.0` OpenSSF-PA C2-domain communicator with dep-confusion inflated pin)
GHSA published 8 npm CWE-506 advisories dated 2026-08-02 - a
houzidawang806/807/808sequential-namespace trio, asimple-date-formatter-util+-1+-2date-utility trio,tailwindcss-animunder the Tailwind CSS ecosystem name shape, andlist-issue-predecessor-dependencies-block@99.0.0flagged by OpenSSF Package Analysis for both malicious-domain communication AND malicious-command execution with the extreme-inflated dep-confusion pin (99.0.0).npmAffected packages8 packages · 8 versions
- npmhouzidawang8061.0.0
- npmhouzidawang8071.0.0
- npmhouzidawang8081.0.0
- npmlist-issue-predecessor-dependencies-block99.0.0
- npmsimple-date-formatter-util1.0.0
- npmsimple-date-formatter-util-11.0.0
- npmsimple-date-formatter-util-21.0.0
- npmtailwindcss-anim1.0.0
npm-2026-08-02-ghsa-malware-sweepSource advisory - npmhouzidawang806
- Critical2 Aug 20262 packages tracked
GitHub Advisory PyPI CWE-506 sweep - 2-package 2026-08-02 batch (`trongriden@0.0.1` Tron/TRX cryptocurrency private-key exfiltration under the long-running `2025-04-tronix` campaign, `wacve-utils@1.0.7` Linux + Android/Termux encrypted infostealer with Telegram exfil)
GHSA published 2 PyPI CWE-506 advisories dated 2026-08-02:
trongriden@0.0.1- Tron/TRX cryptocurrency private-key exfiltration marked as part of the long-running2025-04-tronixcampaign - andwacve-utils@1.0.7, an encrypted infostealer targeting Linux and Android execution under Termux with file system / browser / SMS collection routed to a Telegram channel and remote-script download for dynamic payload updates.PyPIAffected packages2 packages · 2 versions
- PyPItrongriden0.0.1
- PyPIwacve-utils1.0.7
pypi-2026-08-02-ghsa-malware-sweepSource advisory - PyPItrongriden
- Critical1 Aug 202610 packages tracked
GitHub Advisory npm CWE-506 sweep - 10-package 2026-08-01 batch (`test-dev-*` 8-package sequential-namespace burst, `@moxfive-llc/common` scoped RAT, `pp-react-worldready` OpenSSF-PA C2 domain communicator)
GHSA published 10 npm CWE-506 advisories dated 2026-08-01 - an 8-package
test-dev-*sequential-namespace burst (test-dev-boot,-host,-watch,-sync,-dispatch,-exec,-store,-link), a@moxfive-llc/commonscoped RAT publish, andpp-react-worldready@1.0.0flagged by OpenSSF Package Analysis for communicating with a domain associated with malicious activity.npmAffected packages10 packages · 10 versions
- npm@moxfive-llc/common1.0.0
- npmpp-react-worldready1.0.0
- npmtest-dev-boot1.0.0
- npmtest-dev-dispatch1.0.0
- npmtest-dev-exec1.0.0
- npmtest-dev-host1.0.0
- npmtest-dev-link1.0.0
- npmtest-dev-store1.0.0
- npmtest-dev-sync1.0.0
- npmtest-dev-watch1.0.0
npm-2026-08-01-ghsa-malware-sweepSource advisory - npm@moxfive-llc/common
- Critical1 Aug 20267 packages tracked
GitHub Advisory PyPI CWE-506 sweep - 7-package 2026-08-01 batch (`asdk-plugin-*` 3-package dep-confusion trio at `0.0.1`/`9999.0.0`, `walmart-genai-trace` dep-confusion probe, `telerape` PTH-file reverse-shell, `nvtorch-oot-nightly`/`trtllm-subdir-test` NVIDIA-adjacent dep-confusion probe pair at `99999.0.0`/`99999.0.1`)
GHSA published 7 PyPI CWE-506 advisories 2026-08-01:
asdk-plugin-alphagen/-legacy/-ai-platform(dep-confusion trio at0.0.1+9999.0.0),walmart-genai-trace(Walmart internal GenAI namespace probe),telerape(PTH-file reverse-shell persistence), andnvtorch-oot-nightly+trtllm-subdir-test(NVIDIA-adjacent dep-confusion probe pair at99999.0.0/99999.0.1targetingtorch-oot-nightlyand TensorRT-LLM subdir internal namespaces).PyPIAffected packages7 packages · 15 versions
- PyPIasdk-plugin-ai-platform0.0.19999.0.0
- PyPIasdk-plugin-alphagen0.0.19999.0.0
- PyPIasdk-plugin-legacy0.0.19999.0.0
- PyPInvtorch-oot-nightly99999.0.099999.0.1
- PyPItelerape0.0.0.dev01.0.01.0.1
- PyPItrtllm-subdir-test99999.0.099999.0.1
- PyPIwalmart-genai-trace0.0.199.0.0
pypi-2026-08-01-ghsa-malware-sweepSource advisory - PyPIasdk-plugin-ai-platform
- Critical31 Jul 202692 packages tracked
GitHub Advisory npm CWE-506 sweep - 91-package 2026-07-30/07-31 batch (`@peptide-packets` biotech scope pair, socket.io/mongoose/passport typosquat burst, ethers.js/rlp/fs-extra impersonator kit, `nano-perf` postinstall daemon C2, late-07-31 MCP-namespace burst, `@0xlr` dep-confusion PoC scope, `@spending-behavior-ui`/`@finance-ui`/`@mplay-*`/`@sof-assistant-*` enterprise dep-confusion sweep, `rollup-plugin-polyfill-hold`/`-helper` pair, `paraglide-js@1.0.1` takeover-style drop)
GHSA published 91 npm CWE-506 advisories 2026-07-30–07-31: existing 25-pkg batch (
@peptide-packets, socket.io/mongoose/passport typos, ethers/rlp/fs-extra,nano-perfC2) plus a late-07-31 66-pkg wave - MCP-namespace burst (13),@0xlrdep-confusion PoC scope (10), enterprise internal-scope dep-confusion sweep (15 scoped pkgs), broad unscoped typosquats (25),rollup-plugin-polyfill-hold/-helperpair,paraglide-js@1.0.1takeover.npmAffected packages92 packages · 92 versions
- npm@0xlr/clerk-auth1.0.0
- npm@0xlr/dep-confusion-poc1.0.0
- npm@0xlr/prisma-client-js1.0.0
- npm@0xlr/question-types1.0.0
- npm@0xlr/sentry-web1.0.0
- npm@0xlr/stripe-checkout-js1.0.0
- npm@0xlr/stripe-frontend1.0.0
- npm@0xlr/supabase-db1.0.0
- npm@0xlr/test-callback1.0.0
- npm@0xlr/vercel-analytics1.0.0
- npm@404c3s4r/lodash1.0.0
- npm@cr-invested-ui-components/chart1.0.0
- npm@dexwilt/node-fetch2.7.3
- npm@finance-ui/finance-view1.0.0
- npm@finance-ui/snackbar-ifpe1.0.0
- npm@fuji-web-components/maps1.0.0
- npm@global-theme/context1.0.0
- npm@meli-testing/jest-react1.0.0
- npm@mp-op-ss-front-lib/tracks1.0.0
- npm@mplay-core-lib/utilities1.0.0
- npm@mplay-frontend-ui/link1.0.0
- npm@nordic-dev/linting-tools1.0.0
- npm@one-chat/react1.0.0
- npm@peptide-packets/js-unimode1.0.0
- npm@peptide-packets/peptide-modify1.0.0
- npm@sof-assistant-fe-lib/vertical-faqs1.0.0
- npm@spending-behavior-ui/cashflow-widget1.0.0
- npm@spending-behavior-ui/widget-insights1.0.0
- npm@sudoughnym/enviro-demo1.0.0
- npm@sw-commons-components/message-upsell1.0.0
- npmadpanel-core1.0.0
- npmai-backup-script1.0.0
- npmallurectl1.0.0
- npmasdsafsadad1.0.0
- npmasdsafsafdasdsaasdasda1.0.0
- npmattio-discover1.0.0
- npmcapacitor-assets1.0.0
- npmchaos-mcp1.0.0
- npmcommunity-published1.0.0
- npmcreate-remotion1.0.0
- npmeth-bridge1.0.0
- npmethe.json1.0.0
- npmethers.json1.0.0
- npmethersss1.0.0
- npmfast-csv-helper1.0.0
- npmfrontend-regulations1.0.0
- npmfs-extra-master1.0.0
- npmfsextrra1.0.0
- npmgoldenflow-js1.0.0
- npmgtm-mcp-auth1.0.0
- npmhazmat-cfr1.0.0
- npmhit-mcp1.0.0
- npmiac-scanner1.0.0
- npminstall-native-host1.0.0
- npmiwomm-mcp1.0.0
- npmkelly-stake1.0.0
- npmkip-mcp-http1.0.0
- npmmaximumsats-mcp1.0.0
- npmmcp-server-boilerplate1.0.0
- npmmetrics-ui1.0.0
- npmmongostose1.0.0
- npmmoontose1.0.0
- npmnano-perf2.2.0
- npmnode-fs-extra-master1.0.0
- npmnotifications-broadcast1.0.0
- npmparaglide-js1.0.1
- npmpasssport11.0.0
- npmpasstpor1.0.0
- npmpm-claude-skills-mcp1.0.0
- npmpolylabel-web-lib1.0.0
- npmpolyprompt1.0.0
- npmportway1.0.0
- npmprocess-status-widget1.0.0
- npmreact-hot-svg1.0.0
- npmredis-type-xyz1.10.6
- npmrefbase-mcp1.0.0
- npmrlp-master1.0.0
- npmrlp.git1.0.0
- npmrollup-plugin-polyfill-helper1.0.0
- npmrollup-plugin-polyfill-hold1.0.0
- npmrouterbase-mcp1.0.0
- npmsap-mcp-config1.0.0
- npmsap-mcp-facilitator1.0.0
- npmscketio1.0.0
- npmsmart-npv-mcp1.0.0
- npmsoccketio1.0.0
- npmsocketi1.0.0
- npmsocktio1.0.0
- npmsso-users-detection1.0.0
- npmvcse1.0.0
- npmvite-config-svg1.0.0
- npmvite-tsconfig-svg1.0.0
npm-2026-07-31-ghsa-malware-sweepSource advisory - npm@0xlr/clerk-auth
- Critical31 Jul 202614 packages tracked
GitHub Advisory PyPI CWE-506 sweep - 14-package 2026-07-30/07-31 batch (`ml-*-shared` env-var exfil, `ai-perf-toolkit` + `mcp-search-server` cryptominer pair, `phabricator-client@99.x` dep-confusion, plus late-07-31 `2026-07-cognikit` DPRK Contagious Interview cluster and `reguestsc` salatstealer)
GHSA published 14 PyPI CWE-506 advisories 2026-07-30–07-31:
ml-*-sharedenv-var exfil kit (4 pkgs),ai-perf-toolkit+mcp-search-servercryptominer pair,phabricator-client@99.xdep-confusion, plus late-07-31 DPRK Contagious Interview2026-07-cognikitcluster (aiprepkit,catalogai,cognikit,aiassistcore,aichannel,ailaunchkit) andreguestscsalatstealer typosquat.PyPIAffected packages14 packages · 24 versions
- PyPIai-perf-toolkit2.4.2
- PyPIaiassistcore0.1.2
- PyPIaichannel0.1.2
- PyPIailaunchkit0.1.2
- PyPIaiprepkit0.1.2
- PyPIcatalogai0.1.2
- PyPIcognikit0.1.2
- PyPImcp-search-server1.0.02.0.02.0.1
- PyPIml-data-shared12.0.116.0.1
- PyPIml-fdbk-shared1.0.02.3.1
- PyPIml-nps-shared6.0.38.2.3
- PyPIml-shared6.3.08.8.0
- PyPIphabricator-client99.0.099.0.199.0.299.0.399.0.4
- PyPIreguestsc2.34.2
pypi-2026-07-31-ghsa-malware-sweepSource advisory - PyPIai-perf-toolkit
- Critical30 Jul 202628 packages tracked
GitHub Advisory npm CWE-506 sweep - 28-package late 2026-07-29 backfill (`@ai-plus`/`@ai-agent-node` 5-pkg AI-agent SDK cluster, 5-pkg Polymarket / prediction-market impersonator kit, `@peptide-unit` scope pair, 6-pkg Alibaba-adjacent `lzd-*`/`uniapi-*`/`aone-cloud-cli`/`colder-cli`/`lwp-web-client`/`def-open-client` scope, `@zannstore/baileys` 17-version WhatsApp SDK typosquat, misc single-package RATs including `eslintcmd` ESLint typosquat)
GitHub Advisory Database published a further 28 npm CWE-506 advisories dated 2026-07-29 after the prior day's ingest - clusters:
@ai-plus/@ai-agent-node5-pkg AI-agent SDK scopes, 5-pkg Polymarket / prediction-market impersonator kit (polymarket-risk-manager,poly-kelly,ts-precision,ts-bn-proto,stake-math),@peptide-unitpair, 6-pkg Alibaba-adjacent scope,@zannstore/baileys17-version WhatsApp SDK typosquat.npmAffected packages28 packages · 44 versions
- npm@ai-agent-node/agent-node1.0.0
- npm@ai-agent-node/createnode1.0.0
- npm@ai-agent-node/nodesql1.0.0
- npm@ai-plus/de-agent1.0.0
- npm@ai-plus/de-agent-sdk1.0.0
- npm@finxsecdemo/utils1.0.2
- npm@omniwatch-wick/cli1.0.0
- npm@peptide-unit/js-unimode1.0.0
- npm@peptide-unit/peptide-modify1.0.0
- npm@zannstore/baileys2.2.62.2.72.2.82.3.02.3.12.3.22.3.32.3.42.3.52.3.62.3.72.3.92.4.02.4.12.4.22.4.32.4.4
- npmaone-cloud-cli1.0.0
- npmcolder-cli1.0.0
- npmdata-parser-utils1.0.0
- npmdef-open-client1.0.0
- npmeslintcmd1.0.0
- npmfeedback-ai-sdk1.0.0
- npmflight-compare-analyzer1.0.0
- npmlwp-web-client1.0.0
- npmlzd-unified-station-sdk1.0.0
- npmopen-worker-cli1.0.0
- npmpoly-kelly1.0.0
- npmpolymarket-risk-manager1.0.0
- npmstake-math1.0.0
- npmtest-skill-zip1.0.0
- npmts-bn-proto1.0.0
- npmts-precision1.0.0
- npmuniapi-bridge1.0.0
- npmzer0code0.2.0
npm-2026-07-30-ghsa-malware-sweepSource advisory - npm@ai-agent-node/agent-node
- Critical29 Jul 202665 packages tracked
GitHub Advisory npm CWE-506 sweep - 60-package 2026-07-28 → 2026-07-29 backfill (9-package `@wagni_bot/*` Telegram credential-stealer scope, 6-package `2.1.6` postinstall SSH-key + file harvester cluster, 4-package `streak-*` Windows PE binary drop, 3-package `aone-*` embedded-malware trio, `xerohub-discord-voice` Discord-token stealer pair, generic-name C2 domain communicator kit, `@joyfill/*` prerelease pair, misc single-package RATs and typosquats)
GitHub Advisory Database published 6 new npm CWE-506 advisories on 2026-07-29 plus a ~55-package 2026-07-28 backfill. Clusters:
@wagni_bot/*9-pkg Telegram stealer,2.1.6SSH-key harvester (app-*-layer,api-*-sdk),streak-*Windows-PE dropper,aone-*all-versions,xerohub-discord-voicetoken stealer, generic-name C2 kit.npmAffected packages65 packages · 77 versions
- npm@ai_/autoprefixers1.2.0
- npm@apexfnd/apex1.0.01.0.1
- npm@bowozzz/baileys1.0.0
- npm@crbrc/xbt1.1.01.1.11.1.21.1.31.1.41.2.1
- npm@joyfill/components4.0.0-rc24-2773-beta.4
- npm@joyfill/layouts0.1.2-2773.beta.0
- npm@mypwn/hawkeye99.0.0
- npm@wagni_bot/bsc1.0.0
- npm@wagni_bot/eth1.0.0
- npm@wagni_bot/hyperliquid1.0.0
- npm@wagni_bot/metamask1.0.0
- npm@wagni_bot/opensea1.0.0
- npm@wagni_bot/polygon1.0.0
- npm@wagni_bot/polymarket1.0.0
- npm@wagni_bot/wagni1.0.0
- npm@wagni_bot/web31.0.0
- npm@yancyyu/agentcli1.9.32
- npmaone-kit1.0.0
- npmaone-kit-cli1.0.0
- npmaone-sandbox1.0.0
- npmapi-node-sdk2.1.6
- npmapi-rust-sdk2.1.6
- npmapp-sim-layer2.1.6
- npmapp-sima-layer2.1.6
- npmapp-soda-layer2.1.6
- npmapp-svm-layer2.1.6
- npmarray-node-utils1.0.9
- npmarray-sort-helper1.0.0
- npmbasic-vite1.0.0
- npmbianira-ui1.27.0
- npmblots2.1.0
- npmchain-analyze1.0.2
- npmchain-manager1.0.0
- npmcloud-config-fetcher1.0.0
- npmcolor-convert-helper1.0.0
- npmdate-sanitize-helper1.0.0
- npmethers-secure1.0.0
- npmfluid-type-ui2.0.8
- npmjobber-app-template-react1.0.1
- npmjson-schema-inspector1.1.41.1.51.1.61.1.7
- npmjson-to-table-util1.0.0
- npmkordyn0.9.160.9.18
- npmkorvica1.0.0
- npmlib-mtop1.0.0
- npmlib-streak-math1.0.0
- npmlocal-config-parser1.0.0
- npmnode-array-plus1.0.9
- npmnum-format-helper1.0.0
- npmparallely10.0.3
- npmpostcss-motion-utils1.0.0
- npmreact-puller1.0.0
- npmrollup-runtime-core-polyfills0.0.1
- npmsigchain-js1.0.1
- npmsimple-probe-utils1.0.1
- npmsmart-config-manager1.0.0
- npmstreak-core-lib1.0.0
- npmstreak-core-math1.0.0
- npmstreak-daily-lib1.0.0
- npmstring-format-kit1.0.2
- npmtext-line-parser1.0.0
- npmtidal-embed-player1.0.1
- npmtoll_free1.0.1
- npmtriage_bot_using_sdkv32.0.1
- npmxerohub-discord-voice-v21.8.0
- npmxerohub-discord-voice-v33.0.03.0.23.0.3
npm-2026-07-29-ghsa-malware-sweepSource advisory - npm@ai_/autoprefixers
- Critical28 Jul 202654 packages tracked
GitHub Advisory npm CWE-506 mega-sweep - 54-package sample from the 2026-07-27 → 2026-07-28 batch (8-package Ethereum-tooling `curl|bash` typosquat cluster, chalk / express / prettier / prisma / dotenv / chai-as-promised typosquat pairs, "helper/utils/tool/pack" credential+wallet-stealer family, 13-package dep-confusion cluster with `999.x` / `19999.x` / `99.99.99` version-inflation, Shai-Hulud-style preinstall Bun stealer resurgence, `@vaultflow/*` 2026-07-28 pair, `claude-code-base-action` Anthropic typosquat)
GitHub Advisory Database published a mega-batch of 250+ new npm CWE-506 malware advisories on 2026-07-27 (spanning 12+ paginated result pages), plus 2 more on 2026-07-28 (
@vaultflow/create-flow,@vaultflow/update-flow). This module catalogues 54 non-@antvnon-previously-tracked packages from the batch. Notable clusters: 8-package Ethereum-toolingcurl|bashoperator (web3-core-js,truffle-js,truffle-helper,solc-helper,hardhat-core,ethers-common,ethers-io,cdp-core), typosquat pairs (chalk-*,exxpress-*,prettier-lint-lenz,prisma-callback,env-threads), dep-confusion with inflated version numbers (999.x,19999.x,99.99.99), and Shai-Hulud-style preinstall Bun credential stealers onmcp-echarts,mcp-mermaid,ai-figure,gantt-for-react,amapcn,boring-avatars-vanilla,jest-canvas-mock,@cap-js/openapi.npmAffected packages54 packages · 125 versions
- npm@apps-home-dashboard/events11.9.011.9.1
- npm@cap-js/openapi1.4.1
- npm@citi-icg-158830/elemental-chameleon0.0.0-defensive-callback0.0.0-defensive-callback.1
- npm@convera/ui-shared0.0.20.0.3
- npm@datatrain/passenger-v399.99.99
- npm@design-system-coopeuch/web999.0.0999.0.4
- npm@pelmnaads/naads-common-logger19999.0.1
- npm@tc-core/campus-service0.0.0-defensive-callback
- npm@vaultflow/create-flow1.0.0
- npm@vaultflow/update-flow1.0.0
- npm@webapp-next/store91.1.0
- npmai-figure0.5.00.6.0
- npmamapcn0.2.00.2.10.2.20.3.00.3.10.3.2
- npmapex-connector1.0.01.0.11.0.21.0.31.0.4
- npmapex-trading1.0.4
- npmboring-avatars-vanilla1.1.21.2.2
- npmbui-react-10components99.0.0
- npmcache-poisoning-pwn-demo0.1.270.1.280.1.29
- npmcdp-core1.0.41.0.6
- npmchai-as-regulated2.0.102.0.112.0.12
- npmchalk-pack1.0.42.0.0
- npmchalk-utils1.0.31.0.42.0.0
- npmcheerio-tool1.0.31.0.41.0.5
- npmclaude-code-base-action2.0.02.2.2
- npmdotenvv-tool1.0.21.0.31.0.41.0.52.0.0
- npmenv-threads1.5.0
- npmethers-common1.0.02.0.0
- npmethers-io1.0.02.0.0
- npmexxpress-tool1.0.01.0.21.0.5
- npmexxpress-utils1.0.21.0.31.0.52.0.0
- npmgantt-for-react0.3.00.4.0
- npmglob-helper1.0.01.0.11.0.21.0.31.0.41.0.52.0.0
- npmhardhat-core1.0.02.0.0
- npmhello-world-pkg-value-value-p1.0.41.0.11
- npmidentitysecuretokenserv10.0.020.0.0
- npmjest-canvas-mock2.5.32.6.32.7.3
- npmjoi-pack1.0.31.0.41.0.5
- npmmcp-echarts0.8.10.9.1
- npmmcp-mermaid0.5.10.6.1
- npmmotion-forge-css1.0.0
- npmnock-helper1.0.21.0.31.0.41.0.52.0.0
- npmnode-ci-utils2.1.02.1.12.1.22.1.32.1.4
- npmpaysafe-gbp-virtual-assistant-lib-fe2.0.4
- npmprettier-lint-lenz1.0.02.6.4
- npmprisma-callback1.0.01.0.31.0.41.0.5
- npmrequest-logger-canary1.0.0
- npmrimraf-utils1.0.41.0.52.0.0
- npmsolc-helper1.0.02.0.0
- npmsysbin1.0.34
- npmtruffle-helper1.0.02.0.0
- npmtruffle-js1.0.02.0.0
- npmtypography-stylecss0.7.4
- npmvue-template-compiler-plugin2.7.18
- npmweb3-core-js1.0.02.0.0
npm-2026-07-28-ghsa-malware-sweepSource advisory - npm@apps-home-dashboard/events
- Critical28 Jul 20267 packages tracked
GitHub Advisory PyPI CWE-506 sweep - 7-package 2026-07-28 batch (`karpatkit`/`karpatkey` dep-confusion pair against Karpatkey DAO tooling, `dev-helper-bg` + `cfgzen` infostealer siblings, `mrmustard` Xanadu-quantum-lib typosquat, `vtranalytic` Telegram RAT, `govapkg` fake-Go-doc-client with systemd persistence)
GHSA published 7 new PyPI CWE-506 advisories on 2026-07-28:
karpatkit/karpatkeyKarpatkey DAO dep-confusion pair,dev-helper-bg+cfgzeninfostealer siblings,mrmustard@0.7.4Xanadu typosquat,vtranalytic@9.0.1Telegram RAT,govapkg@0.1.0fake Go doc client with systemd persistence.PyPIAffected packages7 packages · 17 versions
- PyPIcfgzen1.0.01.0.11.0.21.0.31.0.41.0.51.0.6
- PyPIdev-helper-bg0.1.30.1.40.1.60.1.7
- PyPIgovapkg0.1.0
- PyPIkarpatkey2.1.1
- PyPIkarpatkit2.1.02.1.1
- PyPImrmustard0.7.4
- PyPIvtranalytic9.0.1
pypi-2026-07-28-ghsa-malware-sweepSource advisory - PyPIcfgzen
- High27 Jul 202646 packages tracked
GitHub Advisory npm CWE-506 sweep - 47-package overnight batch (8-package `thirdweb` / `rainbowkit` crypto-wallet typosquat cluster, 6-package baileys/WhatsApp-scraper `fazz*` + `@vinnxcode` + `sixbails` family, 4-package `log-taker` / `ts-escrow` sibling cluster, 5-package `txs-*` + `chai-log` operator cluster, 3-package `@403name/*` typosquat cluster, 4-package `edu-npm-*` "educational" postinstall family, `@wrenfield/abitype` + `@wrenfield/viem` crypto-SDK typosquats, `@kalipto/local` + `kalipto-runtime`, `@ceeferenderer/*` dep-confusion pair, `ap3-components-ui` v9.999.0 dep-confusion, `permcserver` / `permcarmserver`, plus singletons) retired 2026-07-27 01:02–05:36 UTC
On 2026-07-27 01:02 → 05:36 UTC GitHub retired 47 npm CWE-506 malware advisories in a single overnight batch. Twelve clusters spanning crypto-wallet typosquats (
thirdweb/rainbowkit/@wrenfield/viem), WhatsApp-Baileys scrapers (fazz*,@vinnxcode,sixbails,amanexzyra-baileys), dependency-confusion (ap3-components-ui@9.999.0,@ceeferenderer/*), postinstall droppers (txs-*,chai-log,edu-npm-*,@403name/*), plus singletons. All 47 packages security-replaced with0.0.1-securitysentinel tarballs.npmAffected packages46 packages · 114 versions
- npm@403name/electron-buidler1.0.01.0.11.0.2
- npm@403name/ether-js1.0.01.0.11.0.2
- npm@403name/fsevent1.0.01.0.11.0.2
- npm@ceeferenderer/fe-renderer-sdk9.9.09.9.999.9.9
- npm@ceeferenderer/itg-renderer-sdk9.9.09.9.999.9.9
- npm@ci-lifecycle-test/postinstall-ping1.0.0
- npm@fazzcode/baileys0.1.10.1.50.1.60.1.72.0.62.4.42.5.32.5.42.5.52.5.62.5.7
- npm@kalipto/local1.0.01.0.11.0.21.0.3
- npm@vinnxcode/libsignal-node1.0.01.0.1
- npm@vinnxcode/xbailsync1.0.01.0.1
- npm@wrenfield/abitype1.2.31.2.41.2.61.2.7
- npm@wrenfield/viem2.53.12.53.22.53.32.53.4
- npmamanexzyra-baileys3.0.04.0.04.0.2
- npmap3-components-ui9.999.0
- npmchai-log1.1.0
- npmedu-npm-dependency-chain-demo1.0.01.0.11.0.21.0.31.0.4
- npmedu-npm-helper-alpha1.0.0
- npmedu-npm-helper-beta1.0.0
- npmedu-npm-postinstall-demo21.0.01.0.11.0.21.0.3
- npmfazzanime0.3.20.3.30.3.4
- npmfazzgram0.1.00.1.1
- npmfluterjs1.0.0
- npmjextic-eclib1.0.0
- npmkalipto-runtime1.0.0
- npmlog-taker0.0.70.0.80.0.90.1.0
- npmlog-taker10.1.0
- npmnpx-whoami-demo1.0.0
- npmpermcarmserver1.0.0
- npmpermcserver1.0.01.0.11.0.21.0.31.0.4
- npmrainbokit0.0.8
- npmrainbownkit0.0.8
- npmroblox-api-client1.0.0
- npmsixbails1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.1.01.1.11.1.2
- npmtherdweb0.0.8
- npmthidweb0.0.8
- npmthirdwb0.0.8
- npmthirdwebb0.0.8
- npmthirdwebjs0.0.8
- npmthurdweb0.0.8
- npmts-escro0.0.60.0.70.0.80.0.9
- npmts-escrow0.0.90.1.0
- npmtxs-builder1.0.6
- npmtxs-random-lib1.0.1
- npmtxs-runner-lib1.0.1
- npmtxs-sdk-lib1.0.1
- npmv018-axios-cdntest1.0.01.0.11.0.21.0.3
npm-2026-07-27-ghsa-malware-sweepSource advisory - npm@403name/electron-buidler
- Medium25 Jul 202620 packages tracked
GitHub Advisory npm CWE-506 backfill - 19 "John Wick 4" Spanish-SEO-spam autopublisher packages + `-pem-misa` tea.xyz farmer swept 2026-07-25 (all long-unpublished from npm)
On 2026-07-25 GitHub retired 20 npm CWE-506 malware advisories in a historical backfill batch - 19 SEO-spam autopublisher packages named after the 2023 movie "John Wick: Chapter 4" (all originally published 2023-03-23, unpublished 2023-03-27), plus
-pem-misa@1.3.3(published 2024-05-24, part of the Indonesian tea.xyz token-farming autopublisher wave). No credential-stealer or wallet-drain payload - these are token-farming and SEO-spam packages that have been off the public npm registry for 1-3 years.npmAffected packages20 packages · 20 versions
- npm-accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-allah-varindo-en-casa-lliena-1.0.0
- npm-accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-1.0.0
- npm-espanol-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love1.0.0
- npm-espanol-john-wick-keanu-reeves-4-k-varindo-en-casa-en-lienia-lliena-love1.0.0
- npm-john-wick-4-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love1.0.0
- npm-john-wick-4-keanu-reeves-pelicula-completa-h-d-varindo-en-casa-en-lienia-lliena-love1.0.0
- npm-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-en-lienia-lliena-love1.0.0
- npm-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-espanol1.0.0
- npm-john-wick-4-keanu-reeves-peliculas-completa-h-d-varindo-en-casa-lliena-love1.0.0
- npm-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-1.0.0
- npm-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-lliena-espanol1.0.0
- npm-john-wick-4-keanu-reeves-peliculas-completa-varindo-h-d-varindo-en-casa-tarabi-lliena-1.0.0
- npm-john-wick-keanu-4-k-varindo-en-casa-en-lienia-lliena-love1.0.0
- npm-john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-1.0.0
- npm-john-wick-keanu-reeves-pelicula-completa-4-k-varindo-en-casa-en-lienia-lliena-love1.0.0
- npm-pem-misa1.3.3
- npm-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-1231.0.0
- npm-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-index-main1.0.0
- npm-whare-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-suparhit1.0.0
- npm-whareo-to-watch-john-wick-chapter-4-2023-fullmovies-hd-online-at-home1.0.0
npm-2026-07-25-ghsa-tea-xyz-backfillSource advisory - npm-accion-pelicula-john-wick-4-keanu-reeves-peliculas-completa-varindo-allah-varindo-en-casa-lliena-
- High24 Jul 202610 packages tracked
GitHub Advisory malware sweep - 10-package `svelte-*-streak` / `eth-*` typosquat cluster (`eth-base` / `eth-slint` / `eth-codergen` / `streak-lib-math` / `svelte-streak-metrics`), `chai-as-stringify` `chai` v7 typosquat, `svgcraft-core` 8-version dropper, and `yuinpm` 68-version prolific-publisher cluster swept 2026-07-23 late-batch
On 2026-07-23 15:39 → 20:10 UTC GitHub retired 10 additional npm CWE-506 malware advisories in a later batch beyond the earlier 19-package sweep. Five clusters: 4-package
streak-*/svelte-*-streakextending the 2026-07-21 wave; 3-packageeth-*Ethereum typosquat;chai-as-stringifyv7 typosquat; 8-versionsvgcraft-coredropper; andyuinpm- 68 date-tagged malicious versions.npmAffected packages10 packages · 90 versions
- npmchai-as-stringify7.0.17.0.2
- npmeth-base1.0.0
- npmeth-codergen1.0.01.0.11.0.2
- npmeth-slint1.0.0
- npmstreak-bucket-lib1.0.0
- npmstreak-lib-math1.0.0
- npmsvelte-goal-streak1.0.0
- npmsvelte-streak-metrics1.0.0
- npmsvgcraft-core1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.7
- npmyuinpm2026.7.19-22026.7.19-2-12026.7.19-2-22026.7.19-2-32026.7.19-2-42026.7.19-2-52026.7.19-2-62026.7.19-2-72026.7.19-2-82026.7.19-2-92026.7.19-2-102026.7.19-2-112026.7.19-2-122026.7.20-1-12026.7.20-1-22026.7.20-1-32026.7.20-1-42026.7.20-1-52026.7.20-1-62026.7.20-1-72026.7.20-1-82026.7.20-1-92026.7.20-1-102026.7.20-1-112026.7.20-1-122026.7.20-1-132026.7.20-1-142026.7.20-1-152026.7.20-1-162026.7.20-1-172026.7.20-1-182026.7.20-1-192026.7.20-1-202026.7.20-1-212026.7.20-1-222026.7.20-1-232026.7.20-1-242026.7.20-1-252026.7.20-1-262026.7.20-1-272026.7.20-1-282026.7.20-1-292026.7.20-1-302026.7.20-1-312026.7.20-1-322026.7.20-1-332026.7.20-1-342026.7.22-1-12026.7.22-1-22026.7.22-1-32026.7.22-1-42026.7.22-1-52026.7.22-1-62026.7.22-1-72026.7.22-1-82026.7.22-1-92026.7.22-1-102026.7.22-1-112026.7.22-1-122026.7.22-1-132026.7.22-1-142026.7.22-1-152026.7.22-1-162026.7.22-1-172026.7.22-1-182026.7.22-1-192026.7.22-1-202026.7.22-1-212026.7.22-1-222026.7.22-1-232026.7.22-1-24
npm-2026-07-24-ghsa-malware-sweepSource advisory - npmchai-as-stringify
- High24 Jul 20264 packages tracked
GitHub Advisory malware sweep - 4-package `app-data-*` / `app-node-*` v2.1.6 typosquat cluster (`app-data-layer`, `app-node-layer`, `app-data-ist`, `app-data-lts`) coordinated security-replace on 2026-07-24
On 2026-07-24 17:19:21 → 17:19:45 UTC (a 24-second window) GitHub retired 4 npm CWE-506 malware advisories for a tight
app-*-prefixed typosquat/dependency-confusion cluster:app-data-layer,app-node-layer,app-data-ist,app-data-lts- all published as2.1.6, all detected in a single coordinated pipeline sweep.npmAffected packages4 packages · 4 versions
- npmapp-data-ist2.1.6
- npmapp-data-layer2.1.6
- npmapp-data-lts2.1.6
- npmapp-node-layer2.1.6
npm-2026-07-24-app-cluster-ghsa-sweepSource advisory - npmapp-data-ist
- High23 Jul 202619 packages tracked
GitHub Advisory malware sweep - 6-package crypto-wallet-drainer typosquat cluster (`ethers*` / `bs58-88` / `@bcryptln/*`), 7-package `version-110`/`version-22` dependency-confusion burst (`helix-deploy` / `vue-demi-fix` / `xrblocks-*` / etc.), and 6-package late-July typosquat/misc set swept 2026-07-23
On 2026-07-23 GitHub's Advisory Database retired 19 CWE-506 npm malware advisories in a coordinated 2-hour security-replace window. Three clusters emerge: a 6-package crypto-wallet-drainer typosquat cluster (
ethers-packge,ethers-wallet-package,ethers-wallet-packages,bs58-88,@bcryptln/bcryptjs,@bcryptln/becryptjs) whose names ape theethers,bs58, andbcryptjscrypto/hashing libraries; a 7-packageversion-110/version-22dependency-confusion burst (helix-deploy,vue-demi-fix,xrblocks-remote-control,lychee-norm-cache,create-kumo-project,aio-commerce-lib-app,eslint-angular-react) using deliberately-inflated major versions to shadow internal-registry names; and a 6-package late-July typosquat/misc set (vitest-axios,fs-extra-core,cktool-core,mcp-notes-server-poc-praetorian,base65-85x,da-sc-sdk).npmAffected packages19 packages · 38 versions
- npm@bcryptln/bcryptjs3.0.3
- npm@bcryptln/becryptjs3.0.83.0.93.0.103.0.11
- npmaio-commerce-lib-app110.0.0
- npmbase65-85x5.0.1
- npmbs58-886.0.1
- npmcktool-core1.0.01.0.11.0.21.0.31.0.4
- npmcreate-kumo-project22.0.0
- npmda-sc-sdk1.2.31.2.4
- npmeslint-angular-react110.0.0110.0.1110.0.2
- npmethers-packge2.1.2
- npmethers-wallet-package5.8.0
- npmethers-wallet-packages5.8.05.8.15.8.2
- npmfs-extra-core1.3.4
- npmhelix-deploy110.0.0110.0.1
- npmlychee-norm-cache22.0.0
- npmmcp-notes-server-poc-praetorian0.1.0
- npmvitest-axios1.0.4
- npmvue-demi-fix10.0.010.0.110.0.210.0.310.0.410.0.510.0.6
- npmxrblocks-remote-control22.0.0
npm-2026-07-23-ghsa-malware-sweepSource advisory - npm@bcryptln/bcryptjs
- High22 Jul 20266 packages tracked
GitHub Advisory malware sweep - `encryptstring*` 3-package cluster, `react-tabulix-ui` 3-version burst, `vantora` 2-version pair, and `kijai` singleton swept 2026-07-22
On 2026-07-22 GitHub's Advisory Database retired six CWE-506 npm malware advisories. Dominant cluster: three
encryptstring*packages (encryptstringadmin,encryptstringadmincore,encrypt-string-ttak) with 9 combined versions security-replaced within a 20-second window at 20:37 UTC - a coordinated single-actorencryptstring-themed publish burst. Also swept:react-tabulix-ui3-version burst,vantora2-version pair, and the pre-existingkijaisingleton.npmAffected packages6 packages · 15 versions
- npmencrypt-string-ttak1.0.01.0.11.0.2
- npmencryptstringadmin1.2.11.3.01.4.2
- npmencryptstringadmincore1.0.11.1.01.2.2
- npmkijai0.0.2
- npmreact-tabulix-ui0.1.00.1.10.1.2
- npmvantora1.0.01.0.1
npm-2026-07-22-ghsa-malware-sweepSource advisory - npmencrypt-string-ttak
- High21 Jul 20266 packages tracked
GitHub Advisory malware sweep - 3-package `streak-*` habit-tracker cluster, `@apexfdn/apex` 33-version dependency-confusion burst, `nolby` 4-version rapid-burst, and `veskra` singleton swept 2026-07-21
On 2026-07-21 GitHub's Advisory Database retired six CWE-506 npm malware advisories. Highlights: a 3-package
streak-*habit-tracker cluster (streak-daycount,streak-calendar,svelte-streaks) published within a 56-minute window on 2026-07-21 and security-replaced 8 hours later, a@apexfdn/apex33-version 2.5-week dependency-confusion burst (1.0.0→1.0.32), and anolby4-version 4-hour rapid-burst.npmAffected packages6 packages · 43 versions
- npm@apexfdn/apex1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.111.0.121.0.131.0.141.0.151.0.161.0.171.0.181.0.191.0.201.0.211.0.221.0.231.0.241.0.251.0.261.0.271.0.281.0.291.0.301.0.311.0.32
- npmnolby1.0.01.0.11.0.21.0.3
- npmstreak-calendar1.0.01.0.1
- npmstreak-daycount1.0.0
- npmsvelte-streaks1.0.01.0.11.0.2
- npmveskra
npm-2026-07-21-ghsa-malware-sweepSource advisory - npm@apexfdn/apex
- High21 Jul 2026223 packages tracked
GitHub Advisory PyPI mass backfill - ~10,000 CWE-506 malware advisories published in a single day dominated by yfinance/python-binance/requests/tensorflow typosquats, wallet* crypto-stealer cluster, and xolo/lib*/py-mine* random-blob clusters
On 2026-07-21 GitHub's Advisory Database published a ~10,000-package PyPI CWE-506 malware backfill (400 GHSA pages × 25/page) - the largest single-day GHSA malware batch ever recorded, spanning the entire alphabet in descending order. Dominant themes:
yfinancetyposquats (~20 variants),python-binance/requests/tensorflow/beautifulsoup/websocketstyposquats, awallet*crypto-stealer cluster (~15 packages), axolo*random-name blob cluster (~50 packages), and coordinatedlib{cv,craft,ed}*random-word-combo clusters.PyPIAffected packages223 packages · 0 versions
- PyPIdsicord-webhook
- PyPIeautifulsoup
- PyPIebautifulsoup
- PyPIebautifulsoup4
- PyPIebsocket-client
- PyPIebsockets
- PyPIlibcpumineed
- PyPIlibcraftcontrolcraft
- PyPIlibcraftosintnvidia
- PyPIlibcraftreplaceencode
- PyPIlibcraftsplithacked
- PyPIlibcraftsplitint
- PyPIlibcraftstringcc
- PyPIlibcraftsuperre
- PyPIlibcrypt
- PyPIlibcvcandycontrol
- PyPIlibcvcontrolhydra
- PyPIlibcvcv
- PyPIlibcvcvkill
- PyPIlibcvencode
- PyPIlibcvgetsplit
- PyPIlibcvgrandpep
- PyPIlibcvpiphttp
- PyPIlibcvpippep
- PyPIlibcvproofstr
- PyPIlibcvstred
- PyPIlibcvverstr
- PyPIlibedencodemine
- PyPIlibedlgtbreplace
- PyPIlibedmcpong
- PyPIlibedpephttp
- PyPIpy-mccpu
- PyPIpy-mcedcraft
- PyPIpy-mcloadpaypal
- PyPIpy-mcmcmask
- PyPIpy-mcosint
- PyPIpy-mcpyw
- PyPIpy-mcrand
- PyPIpy-mcrandom
- PyPIpy-mcultracraft
- PyPIpy-mcvirtualpy
- PyPIpy-mineguigrand
- PyPIpy-minelibcc
- PyPIpy-minenvidia
- PyPIpy-minepingsplit
- PyPIpy-minepipram
- PyPIpy-minepyencode
- PyPIpy-minerampy
- PyPIpy-minereplacesuper
- PyPIpy-nvidiacandy
- PyPIpy-nvidiagranded
- PyPIpy-nvidiaguistr
- PyPIpy-nvidiahttppep
- PyPIpy-nvidiahydraget
- PyPIpy-nvidialibhttp
- PyPIpy-nvidiapepcontrol
- PyPIreq-os
- PyPIreq6
- PyPIreq7
- PyPIreqarg
- PyPIreqargs
- PyPIreqeist
- PyPIreqeosts
- PyPIreqesst
- PyPIreqest-2022
- PyPIreqest-dexfree
- PyPIreqests-2
- PyPIreqests-2022
- PyPIreqests-toolbelt
- PyPIreqeuest-2022
- PyPIreqeuest-new
- PyPIreqeuste
- PyPIreqeusts-toolbelt
- PyPIreqeustz
- PyPIreqeuts
- PyPIreqeyst
- PyPIreqiest
- PyPIreqinstall
- PyPIreqjuests
- PyPIreqquest
- PyPIreqquests
- PyPItensorflow-opt
- PyPItensorflowlitex
- PyPItensorflows
- PyPItensroflow
- PyPItenssorflow
- PyPItensxxfxxk
- PyPIterraformness
- PyPItesorflow
- PyPIultrapost
- PyPIultraproof
- PyPIultrasuper
- PyPIultraultra
- PyPIultravm
- PyPIunclesky5910
- PyPIunizip
- PyPIunzipxz
- PyPIupdate-mss
- PyPIupdate-request
- PyPIupdate-requests
- PyPIupdater12
- PyPIupdateuuid4
- PyPIupggrade-requests
- PyPIupgrade-requests
- PyPIupgrade-requestss
- PyPIupgrade-requestt
- PyPIvypeer
- PyPIvyperr
- PyPIvypper
- PyPIvyyper
- PyPIw3b
- PyPIw3b-py
- PyPIw3bt00n
- PyPIw3eb
- PyPIw3socket
- PyPIwallet-utils
- PyPIwallet-utils-pro
- PyPIwalletdecoders
- PyPIwalletdecoderss
- PyPIwalletrpcs
- PyPIwallets-utils
- PyPIwalletsutils
- PyPIwallettron
- PyPIwallettronpy
- PyPIwalletutility
- PyPIwalletweb3
- PyPIxlsxwrietr
- PyPIxlsxwritre
- PyPIxlsxwritter
- PyPIxoloazfgyobkaw
- PyPIxolobwritbrulv
- PyPIxolobzvfburelm
- PyPIxolodyntlnewtp
- PyPIxoloeduccelifz
- PyPIxolofmdvxqvbmp
- PyPIxoloftiqwxxhje
- PyPIxolofyxkotqwko
- PyPIxologrekjlqzxj
- PyPIxolojbxzzttwpk
- PyPIxolojgmnizxche
- PyPIxolojhzyppbsow
- PyPIxololcuakbzbuu
- PyPIxolomjqalvrpmp
- PyPIxolonavrylpbeb
- PyPIxoloowlowpzeke
- PyPIxoloqmotdjpbic
- PyPIxolosafhpodvqo
- PyPIxolosamsdyhcfa
- PyPIxolosxelwsesnp
- PyPIxolotcgstfiguu
- PyPIxoloulfkhiyywc
- PyPIxolovqryjphftd
- PyPIxolowqffntthtb
- PyPIxoloxwmellxliq
- PyPIxoloyuaezcqixu
- PyPIxorg-renderproto
- PyPIxsltproc
- PyPIxsxwriter
- PyPIxwormclient
- PyPIxxlsxwriter
- PyPIxxoo-bale
- PyPIxxx-bale
- PyPIxyq-drama-skill
- PyPIyc-as-client
- PyPIyeahmankema
- PyPIyellorq
- PyPIyellyproxies
- PyPIyffinance
- PyPIyfiance
- PyPIyfiannce
- PyPIyfiinance
- PyPIyfinaance
- PyPIyfinace
- PyPIyfinacne
- PyPIyfinancce
- PyPIyfinancee
- PyPIyfinane
- PyPIyfinanec
- PyPIyfinannce
- PyPIyfinnace
- PyPIyfinnance
- PyPIyfinnce
- PyPIyfnance
- PyPIyfniance
- PyPIygame
- PyPIyolov8mini
- PyPIyoutube-new
- PyPIyoutubebot
- PyPIypsocks
- PyPIypthon-binance
- PyPIysocks
- PyPIyt-api-dlp
- PyPIyt-yson-bindings
- PyPIython-binance
- PyPIyuzo
- PyPIyyfinance
- PyPIzabitog
- PyPIzafira
- PyPIzakuchienne
- PyPIzakuraweb
- PyPIzamino
- PyPIzatta
- PyPIzebo
- PyPIzelixnitro
- PyPIzenomenallib
- PyPIzeubilamouche
- PyPIzhopaorlaaato
- PyPIzip-me
- PyPIziphash
- PyPIzking
- PyPIzlapp
- PyPIzlib1g-dev
- PyPIzlibxjson
- PyPIzlsrc
- PyPIzmaker
- PyPIznomig
- PyPIzorosnitro
- PyPIzproxy
- PyPIzproxy2
- PyPIzscaner
- PyPIzsender
- PyPIztasimb
- PyPIzydnitro
pypi-2026-07-21-ghsa-mass-backfillSource advisory - High20 Jul 202686 packages tracked
GitHub Advisory malware sweep - 5-package AWS/CDK dependency-confusion cluster, `upjsma` 9-version 3-day burst, and 80-package `@gocortexio/npmgremlinbox-*` Cortex red-team validation kit swept 2026-07-20
On 2026-07-20 GitHub's Advisory Database retired 86 CWE-506 npm malware advisories in a single sweep. Highlights: a 5-package AWS/CDK dependency-confusion cluster (
alb-lambda-cdk,s3-lambda-dynamodb-cdk,lambda-cloudwatch-cdk,iot-kfh-s3,lwc-slds-lbc) published within a 20-minute window on 2026-07-18 with high dep-confusion pins,upjsma(9 versions across 3 days), and the 80-package@gocortexio/npmgremlinbox-*red-team validation kit from the Palo Alto Networks Cortex ecosystem tooling org.npmAffected packages86 packages · 95 versions
- npm@gocortexio/npmgremlinbox-agpl-1-02.1.0
- npm@gocortexio/npmgremlinbox-agpl-1-0-only2.1.0
- npm@gocortexio/npmgremlinbox-agpl-1-0-or-later2.1.0
- npm@gocortexio/npmgremlinbox-agpl-3-02.0.12.1.0
- npm@gocortexio/npmgremlinbox-agpl-3-0-only2.1.0
- npm@gocortexio/npmgremlinbox-agpl-3-0-or-later2.1.0
- npm@gocortexio/npmgremlinbox-apsl2.1.0
- npm@gocortexio/npmgremlinbox-arphic-19992.1.0
- npm@gocortexio/npmgremlinbox-artistic-1-02.1.0
- npm@gocortexio/npmgremlinbox-base2.1.0
- npm@gocortexio/npmgremlinbox-busl-1-12.1.0
- npm@gocortexio/npmgremlinbox-c-uda-1-02.1.0
- npm@gocortexio/npmgremlinbox-cal-1-0-combined-work-exception2.1.0
- npm@gocortexio/npmgremlinbox-cc-by-nc-3-0-de2.1.0
- npm@gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-de2.1.0
- npm@gocortexio/npmgremlinbox-cc-by-nc-nd-3-0-igo2.1.0
- npm@gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-de2.1.0
- npm@gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-fr2.1.0
- npm@gocortexio/npmgremlinbox-cc-by-nc-sa-2-0-uk2.1.0
- npm@gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-de2.1.0
- npm@gocortexio/npmgremlinbox-cc-by-nc-sa-3-0-igo2.1.0
- npm@gocortexio/npmgremlinbox-cc-by-nd-3-0-de2.1.0
- npm@gocortexio/npmgremlinbox-cc-by-sa-2-0-uk2.1.0
- npm@gocortexio/npmgremlinbox-cc-by-sa-2-1-jp2.1.0
- npm@gocortexio/npmgremlinbox-cc-by-sa-3-0-at2.1.0
- npm@gocortexio/npmgremlinbox-cc-by-sa-3-0-de2.1.0
- npm@gocortexio/npmgremlinbox-cc-by-sa-4-02.1.0
- npm@gocortexio/npmgremlinbox-cddl-1-02.1.0
- npm@gocortexio/npmgremlinbox-cdla-sharing-1-02.1.0
- npm@gocortexio/npmgremlinbox-cern-ohl-s-2-02.1.0
- npm@gocortexio/npmgremlinbox-cern-ohl-w-2-02.1.0
- npm@gocortexio/npmgremlinbox-copyleft-next-0-3-02.1.0
- npm@gocortexio/npmgremlinbox-copyleft-next-0-3-12.1.0
- npm@gocortexio/npmgremlinbox-cpol-1-022.1.0
- npm@gocortexio/npmgremlinbox-ecos-2-02.1.0
- npm@gocortexio/npmgremlinbox-epl-1-02.1.0
- npm@gocortexio/npmgremlinbox-epl-2-02.1.0
- npm@gocortexio/npmgremlinbox-eupl-1-12.1.0
- npm@gocortexio/npmgremlinbox-eupl-1-22.1.0
- npm@gocortexio/npmgremlinbox-eupl-3-02.1.0
- npm@gocortexio/npmgremlinbox-fdk-aac2.1.0
- npm@gocortexio/npmgremlinbox-gpl-2-02.1.0
- npm@gocortexio/npmgremlinbox-gpl-3-02.1.0
- npm@gocortexio/npmgremlinbox-hippocratic-2-12.1.0
- npm@gocortexio/npmgremlinbox-jpl-image2.1.0
- npm@gocortexio/npmgremlinbox-lgpl-2-02.1.0
- npm@gocortexio/npmgremlinbox-lgpl-2-12.1.0
- npm@gocortexio/npmgremlinbox-lgpl-3-02.1.0
- npm@gocortexio/npmgremlinbox-linux-man-pages-copyleft2.1.0
- npm@gocortexio/npmgremlinbox-malware-c2-beacon2.1.0
- npm@gocortexio/npmgremlinbox-malware-code-obfuscation2.1.0
- npm@gocortexio/npmgremlinbox-malware-credential-harvesting2.1.0
- npm@gocortexio/npmgremlinbox-malware-cryptomining-indicators2.1.0
- npm@gocortexio/npmgremlinbox-malware-install-execution2.1.0
- npm@gocortexio/npmgremlinbox-malware-network-indicators2.1.0
- npm@gocortexio/npmgremlinbox-mpl-1-12.1.0
- npm@gocortexio/npmgremlinbox-mpl-2-02.1.0
- npm@gocortexio/npmgremlinbox-ms-lpl2.1.0
- npm@gocortexio/npmgremlinbox-ncgl-uk-2-02.1.0
- npm@gocortexio/npmgremlinbox-openpbs-2-32.1.0
- npm@gocortexio/npmgremlinbox-osl-3-02.1.0
- npm@gocortexio/npmgremlinbox-polyform-noncommercial-1-0-02.1.0
- npm@gocortexio/npmgremlinbox-polyform-small-business-1-0-02.1.0
- npm@gocortexio/npmgremlinbox-qpl-1-0-inria-20042.1.0
- npm@gocortexio/npmgremlinbox-sendmail-8-232.1.0
- npm@gocortexio/npmgremlinbox-simpl-2-02.1.0
- npm@gocortexio/npmgremlinbox-sspl-1-02.1.0
- npm@gocortexio/npmgremlinbox-tapr-ohl-1-02.1.0
- npm@gocortexio/npmgremlinbox-tpl-1-02.1.0
- npm@gocortexio/npmgremlinbox-typosquat-axios2.1.0
- npm@gocortexio/npmgremlinbox-typosquat-chalk2.1.0
- npm@gocortexio/npmgremlinbox-typosquat-commander2.1.0
- npm@gocortexio/npmgremlinbox-typosquat-express2.1.0
- npm@gocortexio/npmgremlinbox-typosquat-lodash2.1.0
- npm@gocortexio/npmgremlinbox-typosquat-moment2.1.0
- npm@gocortexio/npmgremlinbox-typosquat-react2.1.0
- npm@gocortexio/npmgremlinbox-typosquat-webpack2.1.0
- npm@gocortexio/npmgremlinbox-ucl-1-02.1.0
- npm@gocortexio/npmgremlinbox-unlicense2.1.0
- npm@gocortexio/npmgremlinbox-wxwindows2.1.0
- npmalb-lambda-cdk18.2.22
- npmiot-kfh-s317.3.23
- npmlambda-cloudwatch-cdk0.0.0
- npmlwc-slds-lbc18.9.41
- npms3-lambda-dynamodb-cdk15.10.16
- npmupjsma1.0.581.0.591.0.601.0.611.0.621.0.631.0.641.0.651.0.66
npm-2026-07-20-ghsa-malware-sweepSource advisory - npm@gocortexio/npmgremlinbox-agpl-1-0
- High20 Jul 2026174 packages tracked
GitHub Advisory backfill sweep - ~264 NuGet CWE-506 malware advisories dominated by Solana wallet impersonators, WPF/WinForms UI-kit typosquats, and popular-API impersonators (Zendesk, Binance, Coinbase, Ripple, Stripe, PayPal, Kraken, Kucoin, Huobi, Bybit)
On 2026-07-20 GitHub's Advisory Database published a ~264-package NuGet CWE-506 malware backfill - the largest single-day NuGet sweep on record. Dominant themes: Solana/crypto wallet impersonators (~15 packages:
Solana,SolanaWallet,solananet,solnetplus,solnetall,solnetunified,solnetwallet.net.core), WPF/WinForms UI-kit typosquats (~40 packages:WPF-UI-Net,WpfAnimatedGif.Net,WpfLightToolkit.Net,LiveCharts.net,Bunifu.*), Oracle Cloud SDK impersonators (OCI.DotNetSDK.*, ~25 packages), and crypto-exchange API impersonators (Binance,Kucoin,Kraken,Bybit,Coinbase,Huobi,Ripple).NuGetAffected packages174 packages · 0 versions
- NuGetAlgoTrading
- NuGetAlgoTrading.Net
- NuGetAltcoins
- NuGetAltcoins.Library
- NuGetbinance.csharp
- NuGetBinance.Libary
- NuGetBinance.Library
- NuGetbitcoincore
- NuGetBitcoinLib.Net
- NuGetBlazor.Captcha
- NuGetBlockcore.Networks.Bitcoin.Bc
- NuGetbsure.binsec
- NuGetbsure.utils
- NuGetBunifu
- NuGetBunifu.Form
- NuGetBunifu.GUI
- NuGetBunifu.UI.WinForms.Net
- NuGetBunifu.UI2Winforms
- NuGetBunifu.UI3Winforms
- NuGetBybit.Net.Core
- NuGetCaptchaCsharp
- NuGetCefSharp.WinForm.Net.Core
- NuGetChronos.Platform.Linux.API
- NuGetClipboard.net
- NuGetCodeExecTest
- NuGetCoinbase.Api
- NuGetGetRekt420
- NuGetGoogleReCaptcha.V4
- NuGethackney.core.enums
- NuGethackney.core.jwt
- NuGetHuobi.Net.Core
- NuGetjjrawlins.cdkiampolicybuilderhelper
- NuGetKANYEWESTBRIDGADE
- NuGetKanyeWestBrigade
- NuGetKanyeWestWasRight
- NuGetKeyAuthAPI
- NuGetKrakenExchange.Net.Core
- NuGetKucoin.Net.Core
- NuGetLedgerWallet.Net
- NuGetLfafafa2
- NuGetLfafafa3
- NuGetLib.Harmony.net
- NuGetLibEmbedder.Fody
- NuGetLitecoin
- NuGetLive.Charts.WinForm
- NuGetLiveCharts.net
- NuGetLiveCharts.WinForms.net
- NuGetLiveCharts.Wpf.net
- NuGetMailBee
- NuGetmarkdown-to-html
- NuGetMetroModern.UI2
- NuGetnethereumunified
- NuGetNotifyIcons
- NuGetNotus.Wallet.Utility.Net
- NuGetNughettt.TestPO
- NuGetOCI.DotNetSDK.Ai.speech
- NuGetOCI.DotNetSDK.Ai.vision
- NuGetOCI.DotNetSDK.Apm.config
- NuGetOCI.DotNetSDK.Appmgmtcontrol.Net
- NuGetOCI.DotNetSDK.Certificates.Net
- NuGetOCI.DotNetSDK.Certificatesmanagement.Net
- NuGetOCI.DotNetSDK.Dashboard.service
- NuGetOCI.DotNetSDK.Databasetools.Net
- NuGetOCI.DotNetSDK.Datalabeling.service
- NuGetOCI.DotNetSDK.File.storage
- NuGetOCI.DotNetSDK.Net
- NuGetOCI.DotNetSDK.Ospgateway.Net
- NuGetOCI.DotNetSDK.Osubbillingschedule.Net
- NuGetOCI.DotNetSDK.Osuborganizationsubscription.Net
- NuGetOCI.DotNetSDK.Osubsubscription.Net
- NuGetOCI.DotNetSDK.Osubusage.Net
- NuGetOCI.DotNetSDK.Servicemanager.proxy
- NuGetOCI.DotNetSDK.Threat.intelligence
- NuGetOCI.DotNetSDK.Usage.Net
- NuGetOCI.DotNetSDK.Visualbuilder.Net
- NuGetOCI.DotNetSDK.Waf.Net
- NuGetOpenCvSharp4.WpfExtensions.Net
- NuGetOtpCsharp
- NuGetPathoschild.Stardew.Mod.Build.Config
- NuGetPathoschild.Stardew.ModBuildConfig.Net
- NuGetPayPalMerchant.SDK
- NuGetPDFTron.NETCore.Windows.x64.Net
- NuGetPortable.Xaml.Net
- NuGetppy.osu.Game.Lib
- NuGetPrivacyGate.net
- NuGetpsbuiId
- NuGetPubIishIgnore
- NuGetPublishIgnor
- NuGetRadPdf.Net
- NuGetReactive.GUI.Winforms
- NuGetReaLTaiizor-WinForm
- NuGetReddit.api
- NuGetReothor.Lab.EvilPackage
- NuGetResource.Embedder.Net
- NuGetRg.Plugins.Popups.Net
- NuGetRimworld.Reference.Libary
- NuGetRimworld.References.Net
- NuGetRipple.NetCore.Api
- NuGetRockstar.AssetManager.Infrastructure
- NuGetRSG.Base
- NuGetSanka.UI.WinForms
- NuGetSanka.UI2.WinForms
- NuGetSanka.UI3.WinForms
- NuGetsecurity_hacks
- NuGetseedefender
- NuGetShade.UI.WinForms
- NuGetShade.WPF.Controls
- NuGetSharpCashAddr.Core
- NuGetsharpdefender
- NuGetSimplify.Windows.Forms.Net
- NuGetSkylark.Net
- NuGetSoenneker.Redis.Util.Net
- NuGetSolana
- NuGetsolananet
- NuGetSolanaWallet
- NuGetsolnetall
- NuGetsolnetall.net
- NuGetsolnetplus
- NuGetsolnetunified
- NuGetsolnetwallet.net.core
- NuGetsqzrframework480
- NuGetStl.Blazor.Authentication.Net
- NuGetStl.CommandLine.Net
- NuGetStl.Fusion.Ext.Contracts.Net
- NuGetStl.Fusion.Ext.Services.Net
- NuGetStl.Generators.Net
- NuGetStl.Plugins.Extensions.Net
- NuGetStl.RestEase.Net
- NuGetStl.Rpc.Server.Core
- NuGetStl.Rpc.Server.Net.Fx
- NuGetstripeapi.net
- NuGetSuperpower-Api
- NuGetSyntellect.Winium.Cruciatus.Net
- NuGetSyntellect.Winium.Element
- NuGetSyntellect.Winium.Web.Driver
- NuGetTessa.Analyzer
- NuGetTessa.Compilations
- NuGetTessa.Core
- NuGetTessa.Linux.V2
- NuGetTessa.Net.V2
- NuGetTessa.Postgre.Sql
- NuGetTessa.Server.Net
- NuGetTessa.UI2
- NuGetTessa.Web.Client.Net
- NuGetTessa.Web.Core
- NuGetTessa.Windows.V2
- NuGettest6789.client
- NuGettest6789.latest
- NuGettest6789.v3
- NuGettestt22esttest
- NuGetTheOpenAI.API
- NuGetUI2.Guna.Winforms
- NuGetUltimate.Wpf.Toolkit
- NuGetvspropertypages
- NuGetWhatsapp.API
- NuGetWindowsAPICodePack.Net
- NuGetWinforms
- NuGetWPF-UI-Net
- NuGetWpf.UI.WinForms
- NuGetWpfAnimatedGif.Net
- NuGetWpfLightToolkit.Net
- NuGetWPFMediaKit.Net
- NuGetWpfScreenHelper.Net
- NuGetwpfuihelpercore
- NuGetXam.Plugins.Forms.Svg.Net
- NuGetXboxGamebar
- NuGetxopxopxopxopxopx
- NuGetYoutubeExtractor.Net
- NuGetZendesk
- NuGetZendesk-Api
- NuGetZendesk.Client
- NuGetZendesk.Drivers
- NuGetZendesk.OAuth
- NuGetZendeskApi.Client.V2
nuget-2026-07-20-ghsa-backfill-sweepSource advisory - High18 Jul 20268 packages tracked
GitHub Advisory malware sweep - 8 npm packages (3-package `syft-acp-*` "click2ai" dep-confusion beacon, 2-package `@edgecommons/*` preinstall-hook pair, `axios-native` + `telemetry-axios` axios typosquats, `easyway2` 12-version 4-hour burst) retired 2026-07-17 → 2026-07-18
On 2026-07-17 and 2026-07-18 GitHub's Advisory Database retired 8 CWE-506 npm malware advisories. Highlights: a 3-package
syft-acp-*dependency-confusion trio published by npm accountada8877that beacons victim IP + hostname to a Sentry ingest endpoint (byte-for-byte reuse of the earlier "click2ai" reconnaissance payload), a 2-package@edgecommons/*preinstall-hook pair, and axios typosquatsaxios-native+telemetry-axios.npmAffected packages8 packages · 19 versions
- npm@edgecommons/edgecommons1.0.0
- npm@edgecommons/streamlog-node1.0.0
- npmaxios-native1.0.0
- npmeasyway21.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.11
- npmsyft-acp-atoms14.8.68
- npmsyft-acp-core16.0.0
- npmsyft-acp-uikit1.9.45
- npmtelemetry-axios1.0.0
npm-2026-07-18-ghsa-malware-sweepSource advisory - npm@edgecommons/edgecommons
- High18 Jul 20269 packages tracked
crates.io dependency-confusion burst - 9 Rust crates targeting AWS, Mysten Labs, Replit, Proton, plus 4 generic-name typosquats, all flagged by OpenSSF Package Analysis on 2026-07-18
On 2026-07-18 the OpenSSF Package Analysis project flagged 9 Rust crates as malware - all yanked from crates.io within hours and mirrored into the GitHub Advisory Database as CWE-506 records. The 99.x.x version pins on
mysten-metrics,amzn-codewhisperer-streaming-client,amzn-consolas-client,replit_ruspty,semantic-search-client,supertag,proton-pfff, andlshare classic dep-confusion telltales. Every crate communicates with an attacker-controlled domain and executes commands on install.crates.ioAffected packages9 packages · 11 versions
- crates.ioamzn-codewhisperer-streaming-client99.0.1
- crates.ioamzn-consolas-client99.0.1
- crates.iolittest0.3.1
- crates.iolsh99.0.199.1.0
- crates.iomysten-metrics9.0.09.0.3
- crates.ioproton-pfff99.99.5
- crates.ioreplit_ruspty1.0.0
- crates.iosemantic-search-client99.0.1
- crates.iosupertag99.1.1
crates-2026-07-18-openssf-typosquat-burstSource advisory - crates.ioamzn-codewhisperer-streaming-client
- High18 Jul 20263 packages tracked
GitHub Advisory malware sweep - 3 PyPI packages retired 2026-07-18 (`govpkg` telegra.ph-C2 downloader + persistent fake-service; `trongridev`/`trongridme` Tron private-key exfil pair)
On 2026-07-18 GitHub's Advisory Database retired 3 CWE-506 PyPI malware advisories. Highlights:
govpkg(versions 0.1.0, 0.2.0 - the OSSF-tagged2026-07-govpkgcampaign) silently downloads a native executable, disguises it as a system service for persistence, and usestelegra.ph(Telegraph anonymous-publishing) as C2; and atrongridev/trongridmeTron private-key exfil pair (both v0.0.1) from the recurring OSSF2025-04-tronixcampaign.PyPIAffected packages3 packages · 4 versions
- PyPIgovpkg0.1.00.2.0
- PyPItrongridev0.0.1
- PyPItrongridme0.0.1
pypi-2026-07-18-ghsa-malware-sweepSource advisory - PyPIgovpkg
- High18 Jul 20263 packages tracked
SleeperGem - dormant RubyGems maintainer takeover drops persistent developer-laptop backdoor via `git.disroot.org` Forgejo second-stage (git_credential_manager, Dendreo, fastlane-plugin-run_tests_firebase_testlab)
On 2026-07-18 → 07-19 an actor reactivated two long-dormant RubyGems maintainer accounts (Dendreo, dormant since 2020; fastlane-plugin-run_tests_firebase_testlab, dormant since 2019) and published a brand-new
git_credential_managergem impersonating Microsoft's Git Credential Manager. Seven malicious releases across three gems fetch a second-stage binary fromgit.disroot.org/git-ecosystem/*(Forgejo), skip execution if any of ~30 CI env vars are present, and drop a persistent native daemon on developer laptops.RubyGemsAffected packages3 packages · 7 versions
- RubyGemsDendreo1.1.31.1.4
- RubyGemsfastlane-plugin-run_tests_firebase_testlab0.3.2
- RubyGemsgit_credential_manager2.8.02.8.12.8.22.8.3
rubygems-2026-07-18-sleepergem-dormant-maintainer-takeoverSource advisory - RubyGemsDendreo
- High17 Jul 202612 packages tracked
"Polymarket Trap" - fake arbitrage-bot repo funnels DeFi devs to a 30-package infostealer cluster
SafeDep and Panther jointly disclosed the "Polymarket Trap" on 2026-07-17: a fake
Trum3it/polymarket-arbitrage-botGitHub repo (36 stars, 53 forks) whosepackage.jsondeclaresclob-client-mathas a peer utility that is neverimported. The 30-package cluster spans 10 coordinated npm accounts under two profiles - Polymarket / CLOB SDK impersonators (clob-client-math,polymarket-stake-math,polymarket-tradeand siblings) and DeFi-math typosquats (bn-lint,ts-precision,decimal-format-utils). Apostinstallhook drops a 2,787–2,887-line JavaScript infostealer that harvests crypto wallets, browser vaults, SSH keys, cloud tokens, and password-manager databases.npmAffected packages12 packages · 29 versions
- npmbn-lint3.0.63.0.8
- npmclob-client-math1.0.01.0.1
- npmdecimal-format-utils1.0.01.0.1
- npmpolymarket-ai-agent0.1.00.1.1
- npmpolymarket-auto-trade0.1.00.1.1
- npmpolymarket-bot0.1.00.1.1
- npmpolymarket-claude-code0.1.00.1.1
- npmpolymarket-copy-trading0.1.00.1.1
- npmpolymarket-stake-math3.1.03.2.03.3.03.4.03.5.03.5.1
- npmpolymarket-stake-maths3.1.03.2.03.3.03.5.2
- npmpolymarket-trade0.1.00.1.1
- npmts-precision3.7.2
npm-2026-07-17-polymarket-trap-clob-client-mathSource advisory - npmbn-lint
- High16 Jul 202618 packages tracked
GitHub Advisory malware sweep - 18 npm packages (2 Claude / Anthropic-brand typosquats, 3-package `chain-sdk-js` / `theta-sdk-js` / `ai-pro-sdk` mid-July SDK cluster, 3-package `ai-p2p` / `websight-p2p` / `websight2-p2p` June 15 P2P burst, 3 auto-publisher sleepers `px8my` (55 versions) / `monogrok` (21 versions) / `scan-only` (16 versions), plus WordPress Gutenberg / terminal-toy / singleton fillers) retired 2026-07-16 → 2026-07-17
On 2026-07-16 and 2026-07-17 GitHub's Advisory Database retired 18 CWE-506 npm malware advisories (separate from 2 additional
chai-as-*retirements folded into the existing jsonspack DPRK incident). Highlights:anthropic-claude-latest- a version-matched (4.7.1/4.7.2/4.7.3) typosquat of Anthropic's Claude Code CLI - andclaude-token-tracker-mcp, an MCP-shape package targeting Claude Code's OAuth-token traffic (matching the Mitiga Labs "MCP token theft" attack chain that abuses.claude.json).npmAffected packages18 packages · 154 versions
- npmai-p2p1.0.01.0.11.0.21.0.31.0.4
- npmai-pro-sdk2.0.12.0.22.0.32.0.4
- npmanthropic-claude-latest4.7.14.7.24.7.3
- npmawesome-terminal1.0.11.0.21.0.31.0.4
- npmchain-sdk-js1.0.21.0.31.0.41.0.51.0.6
- npmclaude-token-tracker-mcp1.0.0
- npmhehehe1.0.01.0.41.0.51.0.61.0.72.0.12.0.2
- npmloader12.1.22.1.32.1.42.1.52.1.62.1.7
- npmmonogrok1.0.11.0.71.0.81.0.111.0.141.0.301.0.311.0.321.0.331.0.341.0.351.0.361.0.371.0.391.0.401.0.411.0.431.0.44
- npmmy-tailwind-gutenberg-block0.1.00.1.20.1.30.1.40.1.5
- npmpx8my1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.111.0.121.0.131.0.141.0.151.0.161.0.171.0.181.0.191.0.201.0.211.0.221.0.231.0.241.0.251.0.261.0.271.0.281.0.291.0.301.0.311.0.321.0.331.0.341.0.351.0.361.0.371.0.381.0.391.0.401.0.411.0.421.0.431.0.441.0.451.0.461.0.471.0.481.0.491.0.501.0.511.0.521.0.531.0.54
- npmscan-only0.2.00.3.00.4.00.4.10.4.20.4.30.4.40.4.50.4.60.4.70.4.80.4.90.5.00.5.11.0.0
- npmterminal-mascot1.0.01.0.11.0.21.0.33.5.23.5.3
- npmtheta-sdk-js1.2.141.2.151.2.161.2.17
- npmvor8zakon1.0.0
- npmwebsight-p2p1.0.01.0.11.0.21.0.31.0.41.0.51.0.6
- npmwebsight2-p2p1.0.01.0.11.0.21.0.31.0.4
- npmwordpad-text-ui1.0.01.0.11.0.2
npm-2026-07-16-ghsa-malware-sweepSource advisory - npmai-p2p
- High15 Jul 202625 packages tracked
GitHub Advisory malware sweep - 25 npm packages (6-package `@sauruslord` / `zaldy-baileys` WhatsApp-Baileys-fork cluster, 4-package `webpack-cache-*` / `vite-config-optimizer` 35-day dep-confusion sleeper, `patientdocuments` + `fhirproxy-utils` FHIR/healthcare pair, `@bcs-mi-ui` 3-package internal cluster, `js-shared-modules` scope-pair) retired 2026-07-15
On 2026-07-15 GitHub's Advisory Database retired 25 CWE-506 npm malware advisories in four clean bursts. Highlights: a 6-package
@sauruslord/zaldy-baileys/saurus-assetsBaileys WhatsApp-API fork cluster (retired inside a 65-second window at 05:11-05:12 UTC - same operator signature as the earlier@skyzopedia/baileys-modandlotusbailWhatsApp-message-stealer campaigns), a 4-packagewebpack-cache-cycle/webpack-session-cache/webpack-cache-reset/vite-config-optimizer35-day sleeper retired in a 15-second burst, and a healthcare-targetedpatientdocuments@75.0.0+fhirproxy-utilsFHIR-namespace dep-confusion pair.npmAffected packages25 packages · 56 versions
- npm@achuthvp/postinstall-poc1.0.01.0.11.0.21.0.3
- npm@bcs-mi-ui/message1.0.2
- npm@bcs-mi-ui/message-block1.0.2
- npm@bcs-mi-ui/test1243npmpacket761.0.2
- npm@hkyyy/portal-widget-helper-06011.0.0
- npm@saladin0x1/js-shared-modules1.11.6
- npm@sauruslord/baileys1.0.01.0.1
- npm@sauruslord/eslint-config2.0.12.0.2
- npm@sauruslord/libsignal2.0.0
- npmfhirproxy-utils1.0.8
- npmgpu-accelerator1.4.21.4.31.4.41.4.51.4.61.4.7
- npmjs-shared-modules1.11.61.11.7
- npmldpbootstrap-jquery1.0.01.0.21.0.31.0.41.0.51.0.61.0.71.0.91.0.101.0.111.0.121.0.131.0.141.0.151.0.16
- npmpatientdocuments75.0.0
- npmpostcss-processor-utils1.0.01.0.11.0.21.0.3
- npmsaurus-assets1.0.0
- npmsauruslord-baileys1.0.22.0.03.0.2
- npmssweb-wp1.0.0
- npmtestzapier1.0.01.0.1
- npmtextshape-css1.0.0
- npmvite-config-optimizer1.1.4
- npmwebpack-cache-cycle0.1.4
- npmwebpack-cache-reset0.1.4
- npmwebpack-session-cache0.1.4
- npmzaldy-baileys2.0.0
npm-2026-07-15-ghsa-malware-sweepSource advisory - npm@achuthvp/postinstall-poc
- Critical14 Jul 20264 packages tracked
AsyncAPI npm org compromised - 4 packages / 5 versions ship Miasma botnet loader via GitHub Actions `pull_request_target` pwn request
On 2026-07-14 an attacker exploited a
pull_request_targetmisconfiguration inasyncapi/generatorto steal a highly-privileged GitHub PAT, then published five malicious@asyncapi/*releases through the project's own trusted GitHub Actions release pipeline - valid npm OIDC provenance and all. The payload fires onrequire(), spawns a detached Node process, fetches an 8.25 MB IPFS loader (Miasma), and installs a 3.09 MB implant with six independent C2 channels (HTTP, Nostr, IPFS, BitTorrent DHT, libp2p GossipSub, Ethereum smart contract). Combined weekly downloads: ~2.9M.npmAffected packages4 packages · 5 versions
- npm@asyncapi/generator3.3.1
- npm@asyncapi/generator-components0.7.1
- npm@asyncapi/generator-helpers1.1.1
- npm@asyncapi/specs6.11.2-alpha.16.11.2
npm-2026-07-14-asyncapi-miasma-actions-pwn-requestSource advisory - npm@asyncapi/generator
- High14 Jul 20268 packages tracked
PhantomSync - 8-package npm crypto-developer cluster with delayed self-persisting dropper
Between 2026-07-13 and 2026-07-14 the npm publisher
solbuilder_io(angel_lopez89@proton.me) shipped eight small crypto-developer packages -base58-utils,abi-encode,eth-dev,arb-kit,layer2-sdk,solana-key-utils,eth-wallet-helpers,crypto-validate-lib- each carrying a working utility plus a self-invoking dropper that fires ~37s after import, installs cross-platform persistence, and launches an RSA-4096 crypto-wallet stealer exfiltrating to public IPFS. npm-support unpublished every version on 2026-07-14 17:23 UTC.npmAffected packages8 packages · 31 versions
- npmabi-encode1.0.01.0.11.0.21.0.31.0.4
- npmarb-kit1.0.01.0.1
- npmbase58-utils1.0.01.0.11.0.31.0.41.0.5
- npmcrypto-validate-lib1.0.01.0.11.0.21.0.3
- npmeth-dev1.0.01.0.11.0.21.0.31.0.4
- npmeth-wallet-helpers1.0.01.0.11.0.21.0.3
- npmlayer2-sdk1.0.01.0.1
- npmsolana-key-utils1.0.01.0.11.0.21.0.3
npm-2026-07-14-phantomsync-crypto-wallet-dropperSource advisory - npmabi-encode
- High13 Jul 202614 packages tracked
GitHub Advisory malware sweep - 14 npm packages (10-package `getd-*` / `get*` 40-day Spanish-enterprise sleeper cluster, `pure-folder-three` poisoned bump, `dotnet-runtime-base` fresh burst, `node-sysmetrics`, `@jplopezy/connectivity-test-do-not-install`) retired 2026-07-13
On 2026-07-13 GitHub's Advisory Database retired 14 CWE-506 npm malware advisories. The main event is a 10-package
getd-*/get*Spanish-enterprise dep-confusion sleeper cluster (all0.0.1published in a 22-second burst 2026-06-03 13:48–13:49 UTC, dormant for 40 days, then retired in a 47-second take-down burst at 04:51–04:52 UTC). Also included: a maintainer-takeover-style poisoned bump onpure-folder-three@0.7.3,dotnet-runtime-base@{1.0.4,1.0.5}in a same-day fresh burst,node-sysmetrics@1.0.0, and@jplopezy/connectivity-test-do-not-install.npmAffected packages14 packages · 20 versions
- npm@jplopezy/connectivity-test-do-not-install0.0.0-test
- npmdotnet-runtime-base1.0.41.0.5
- npmgetd-content-management0.0.1
- npmgetd-eslint-rules0.0.1
- npmgetd-handler-api0.0.1
- npmgetd-pantallas-cliente0.0.1
- npmgetd-transactional-web0.0.1
- npmgetd-typescript-eslint-rules0.0.1
- npmgetd-ui-library0.0.1
- npmgetd-web-corporativa0.0.1
- npmgethandler-api0.0.1
- npmgetui-library0.0.1
- npmnode-sysmetrics1.0.01.0.1
- npmpure-folder-three0.5.00.6.00.7.00.7.10.7.3
npm-2026-07-13-ghsa-malware-sweepSource advisory - npm@jplopezy/connectivity-test-do-not-install
- High11 Jul 202611 packages tracked
GitHub Advisory malware sweep - 11 npm packages (Higher Logic / AT&T eBiz / Amtrav / babel-eslint dep-confusion continuation, `type-*` 3.3.7 micro-cluster, `authvaultx` + `auth-next-gen` auth-typosquat pair) taken down 2026-07-10 / 2026-07-11
On 2026-07-10 (late-day) and 2026-07-11 GitHub's Advisory Database retired 11 CWE-506 npm malware advisories that arrived after the earlier 2026-07-10 sweep. Highlights: enterprise dependency-confusion continuation (
@higherlogic/ocfe,@att-ebiz/abs-components-bc,@amtrav/webservice,babel-eslint-parser-legacy- all99.9.1race pins staged 2026-07-07 08:25–08:31 UTC), atype-elint/type-plint/type-atobmicro-cluster (all3.3.7, published 2026-07-10 14:13–15:30 UTC), and anauthvaultx+auth-next-genauth-typosquat pair replaced 2026-07-11 00:06 UTC.npmAffected packages11 packages · 12 versions
- npm@amtrav/webservice99.9.1
- npm@att-ebiz/abs-components-bc99.9.9
- npm@higherlogic/ocfe99.9.1
- npmauth-next-gen1.7.11
- npmauthvaultx1.0.0
- npmbabel-eslint-parser-legacy99.9.1
- npmpolipoli-pak1.0.11.0.2
- npmryan-pdf-js1.0.0
- npmtype-atob3.3.7
- npmtype-elint3.3.7
- npmtype-plint3.3.7
npm-2026-07-11-ghsa-malware-sweepSource advisory - npm@amtrav/webservice
- Critical11 Jul 20261 package tracked
Official `jscrambler` npm package compromised - 5 malicious releases drop a cross-platform Rust infostealer (Chrome/Brave/Edge/Chromium profiles, Bitwarden vault, Steam sessions, cloud metadata, MetaMask/Phantom/Exodus wallets)
On 2026-07-11 15:12 UTC the official
jscramblernpm package was hijacked via thejscrambler_maintainer account. Five malicious releases (8.14.0,8.16.0,8.17.0,8.18.0,8.20.0) shipped a Rust infostealer that harvests Chromium browser profiles, the Bitwarden vault, Steam sessions, AWS/Azure/GCP credentials, and MetaMask/Phantom/Exodus wallet seeds.npmAffected packages1 package · 5 versions
- npmjscrambler8.14.08.16.08.17.08.18.08.20.0
npm-2026-07-11-jscrambler-rust-infostealerSource advisory - npmjscrambler
- High10 Jul 202625 packages tracked
GitHub Advisory malware sweep - 25 npm packages (Epic Games / Unreal Engine internal-scope dependency-confusion cluster, LuminaryCloud, Reddit Voyager, nodemon family) taken down 2026-07-09 / 2026-07-10
On 2026-07-09 and 2026-07-10 GitHub's Advisory Database retired 25 CWE-506 Embedded Malicious Code npm advisories. The main story is a coordinated dependency-confusion burst against internal enterprise namespaces - Epic Games / Unreal Engine build tooling (
robomerge,unreal-horde-dashboard,ue-jenkins-buildkite,ue-automation-scripts,epic-internal-tools), LuminaryCloud (@luminarycloudinternal/*), Reddit-style Voyager UI (voyager-web,searchresults), plus workspace/microsite scopes - all replaced by npm Security within a 12-minute window on 2026-07-10 02:57–03:10 UTC. A smaller tail ofnodemon-*/chai-redirection/paperclip-adapter-helperstyposquats and 2026-07-09 throwaways (none123s,tslint-conf) rounds out the sweep.npmAffected packages25 packages · 25 versions
- npm@businessapp-microsites/apis99.9.9
- npm@kl-starfish/test-012.0.0
- npm@luminarycloudinternal/frodo99.9.9
- npm@luminarycloudinternal/lcvis-st99.9.9
- npmchai-redirection1.0.0
- npmcrypto-promiser1.0.0
- npmcursed-ecto-d3ab001.0.0
- npmepic-internal-tools99.9.9
- npmnodemon-gulp1.0.0
- npmnodemon-patch1.0.0
- npmnodemon-sudo1.0.0
- npmnodepack-daemon1.0.0
- npmnone123s1.0.0
- npmpaperclip-adapter-helpers1.0.0
- npmrobomerge99.9.9
- npmsearchresults99.9.9
- npmtslint-conf1.0.0
- npmtxs-builder-lib1.0.0
- npmue-automation-scripts99.9.9
- npmue-jenkins-buildkite99.9.9
- npmunreal-horde-dashboard99.9.9
- npmvoyager-web99.9.9
- npmvps-new-manager1.0.0
- npmworkspace-lint99.9.9
- npmworkspace-scripts99.9.9
npm-2026-07-10-ghsa-malware-sweepSource advisory - npm@businessapp-microsites/apis
- High8 Jul 202620 packages tracked
GitHub Advisory malware sweep - 20 npm packages (Claude-Code / Vue-CLI "clavue" typosquat cluster, `na-rony` throwaway sextet, tailwind-core, common-tg-service six-month sleeper) taken down 2026-07-08 / 2026-07-09
On 2026-07-08 and 2026-07-09 GitHub's Advisory Database retired ~20 CWE-506 Embedded Malicious Code npm advisories, continuing the July take-down cadence at ~20 packages/day. Two distinct clusters: a
clavue/ Claude-Code typosquat family (myclaude-code,clavue,clavuepro,calvuepro,clavue-agent-sdk) targeting Anthropic AI CLI developers; and a *`na-ronythrowaway sextet** - six packages published by one operator between 2026-07-08 03:22–03:39 UTC. Plus atailwind-coretyposquat carrying a real4.3.xversion history and the six-month sleepercommon-tg-service` with 547 versions.npmAffected packages20 packages · 254 versions
- npm@calm2026/imux1.9.11.10.01.10.21.10.31.10.41.11.0
- npm@vite-ln/build-ts5.15.105.17.0
- npmams-ssk1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.111.0.121.0.131.0.141.0.151.0.161.0.171.0.181.0.191.0.201.0.211.0.221.0.231.0.241.0.251.0.261.0.271.0.281.0.291.0.311.0.33
- npmcalvuepro0.1.0
- npmclavue8.8.578.9.08.9.18.9.29.0.09.0.19.0.29.0.39.0.49.0.59.0.69.0.79.1.09.1.19.2.09.2.19.2.29.2.39.2.49.3.09.4.09.4.19.4.29.4.39.4.49.4.59.4.69.4.79.4.89.4.99.4.109.4.119.5.09.5.19.5.29.6.09.6.19.7.09.7.19.7.29.7.39.8.09.8.19.9.09.10.09.10.19.10.29.10.39.10.49.11.09.11.19.11.29.11.39.11.49.11.59.11.69.11.79.12.09.13.09.14.09.14.19.15.09.16.09.22.09.26.010.0.110.0.210.0.310.0.410.1.010.1.110.1.210.1.310.2.010.2.110.2.210.2.310.2.410.3.010.3.110.3.210.4.010.4.110.4.2
- npmclavue-agent-sdk0.2.20.2.30.2.40.2.50.2.60.2.70.2.80.2.90.3.00.3.10.4.00.5.00.6.00.6.10.7.00.7.10.7.20.7.30.7.40.8.00.9.01.0.11.0.21.0.31.0.41.0.51.0.62.0.02.2.0
- npmclavuepro1.0.0
- npmcommon-tg-service1.0.1011.1.991.2.1001.3.247
- npmgas-log1.1.01.1.1
- npmkarem-dp99.9.9
- npmmci-sdk1.2.81.2.91.2.101.2.111.2.121.2.13
- npmmyclaude-code8.8.88.8.98.8.118.8.128.8.138.8.148.8.168.8.178.8.188.8.198.8.208.8.218.8.228.8.238.8.248.8.258.8.268.8.278.8.288.8.308.8.318.8.328.8.338.8.348.8.358.8.378.8.388.8.398.8.408.8.418.8.428.8.43-beta.08.8.43-beta.18.8.43-beta.28.8.43-beta.38.8.43-beta.48.8.43-beta.58.8.43-beta.68.8.43-beta.78.8.43-beta.88.8.43-beta.98.8.43-beta.108.8.43-beta.118.8.448.8.458.8.468.8.478.8.488.8.498.8.508.8.518.8.528.8.538.8.548.8.558.8.568.8.57
- npmna-rony1.1.21.1.31.1.41.1.599.9.9
- npmna-rony-test99.9.9
- npmna-rony-test-karem1.0.0
- npmnam-os-a-man1.0.0
- npmpromo-helper1.0.01.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.111.0.121.0.131.0.141.0.151.0.16
- npmrony-testing99.9.9
- npmtailwind-core0.0.04.3.04.3.14.3.2
- npmvite-json-pwa1.1.11.1.2
npm-2026-07-08-ghsa-malware-sweepSource advisory - npm@calm2026/imux
- Critical8 Jul 202617 packages tracked
@injectivelabs/sdk-ts + 16 sibling packages compromised - wallet-key stealer shipped via GitHub maintainer takeover
On 2026-07-08 20:59 UTC an attacker with a compromised maintainer GitHub account published
@injectivelabs/sdk-ts@1.20.21and pinned the same1.20.21version across 16 sibling@injectivelabs/*wallet + core packages. The malicious release hookedfromMnemonicandfromHexwith atrackKeyDerivationtelemetry stub that base64-encoded stolen mnemonics/private keys and POSTed them totestnet.archival.chain.grpc-web.injective.network. Injective Labs replaced with1.20.23about 49 minutes later; 310 downloads shipped in the window.npmAffected packages17 packages · 17 versions
- npm@injectivelabs/exceptions1.20.21
- npm@injectivelabs/networks1.20.21
- npm@injectivelabs/sdk-ts1.20.21
- npm@injectivelabs/ts-types1.20.21
- npm@injectivelabs/utils1.20.21
- npm@injectivelabs/wallet-base1.20.21
- npm@injectivelabs/wallet-core1.20.21
- npm@injectivelabs/wallet-cosmos1.20.21
- npm@injectivelabs/wallet-cosmos-strategy1.20.21
- npm@injectivelabs/wallet-evm1.20.21
- npm@injectivelabs/wallet-ledger1.20.21
- npm@injectivelabs/wallet-magic1.20.21
- npm@injectivelabs/wallet-private-key1.20.21
- npm@injectivelabs/wallet-strategy1.20.21
- npm@injectivelabs/wallet-trezor1.20.21
- npm@injectivelabs/wallet-turnkey1.20.21
- npm@injectivelabs/wallet-wallet-connect1.20.21
npm-2026-07-08-injectivelabs-sdk-ts-crypto-wallet-drainSource advisory - npm@injectivelabs/exceptions
- High7 Jul 202662 packages tracked
GitHub Advisory malware sweep - ~65 npm packages (AI-SDK typosquat cluster, Solana base58/wallet drainers, SQLite scoped fakes, Nuxt/Chai continuation) taken down 2026-07-07 / 2026-07-08
On 2026-07-07 GitHub's Advisory Database retired ~65 CWE-506 Embedded Malicious Code npm advisories (plus a small 2-package 2026-07-08 tail), the second-largest single-day 2026 GHSA npm-malware sweep after 2026-07-06. Distinct clusters: an AI-SDK typosquat family (
openai-agents-helpers,ollama-helpers,anthropic-toolkit,@langgraphjs/toolkit,ai-sdk-helpers,mcp-server-pg), Solanabase58wallet-drainer names,@sqlite-list/*/@sqlite-access/*throwaway scopes, Nuxt/Chai continuations, plus thewhs4_*sextet.npmAffected packages62 packages · 212 versions
- npm@43uh3ig43/telemetry-client99.0.1
- npm@apexcraft/nano-key1.2.41.2.51.3.21.3.3
- npm@aspect-security/argon21.0.01.0.1
- npm@engagehub/core99.0.0
- npm@engagehub/test-claim1.0.0
- npm@langgraphjs/toolkit1.2.13
- npm@sqlite-access/nodesql1.0.2
- npm@sqlite-list/createsql1.0.0
- npm@sqlite-list/schema-generator1.0.2
- npm@sqlite-list/sql-creator1.0.61.0.7
- npmai-sdk-helpers1.4.5
- npmannotator-harvardx9.0.2
- npmanthropic-toolkit1.3.1
- npmbase58-cli1.0.01.0.11.0.21.0.31.0.41.0.5
- npmbase58-core1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.101.0.111.0.12
- npmbrunomenozzi-test-pkg1.0.0
- npmchai-chain-dom1.3.71.3.81.3.9
- npmchai-sdk1.4.71.4.8
- npmchai-spycore1.1.01.5.3
- npmcrypto-base581.0.01.0.11.0.21.0.31.0.4
- npmdebugcli4.3.44.3.54.3.64.3.74.3.84.3.94.4.1
- npmevm-typechain0.5.4
- npmexpress-deflect1.3.11.6.91.6.101.6.12
- npmexpress-firegate1.3.51.4.01.4.51.4.61.5.11.5.51.6.11.6.31.6.51.6.71.6.81.6.9
- npmgen-ai-opt-in99.0.099.0.199.0.2
- npmharmony-enablers-test-20261.0.0
- npmhello244a1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.111.0.121.0.131.0.141.0.151.0.161.0.171.0.181.0.191.0.201.0.211.0.221.0.231.0.241.0.251.0.261.0.271.0.281.0.291.0.301.0.311.0.321.0.331.0.341.0.351.0.361.0.371.0.381.0.391.0.401.0.411.0.421.0.431.0.441.0.45
- npmhook-augmenting-module99.0.3
- npmjsf-utils0.3.11.3.1
- npmload-nuxt99.0.3
- npmload-nuxt-dev99.0.3
- npmmcp-server-pg0.1.00.1.10.1.20.1.30.2.00.2.10.3.00.3.10.4.00.5.00.6.00.7.00.8.00.9.01.0.01.0.11.1.01.1.11.2.01.2.11.2.2
- npmnodemon-node3.1.16
- npmnonexistent-package99.0.3
- npmnotifier-utils1.3.71.3.81.3.91.4.0
- npmnuxt-fonts-devtools99.0.3
- npmollama-helpers1.2.3
- npmopenai-agents-helpers1.3.3
- npmpinokio-redis1.0.127
- npmpolytrade2.4.1
- npmrnx-align-deps99.0.7
- npmruntimedev-link1.0.01.0.11.0.21.0.31.0.51.0.61.0.81.0.91.0.101.0.111.0.121.0.131.0.14
- npmshopify-internel99.0.1
- npmsolana-address-codec1.0.01.0.11.0.21.0.31.0.41.0.5
- npmsome-theme99.0.3
- npmsyco11.0.31.0.41.0.5
- npmsypoi11.0.01.0.11.0.2
- npmtailwind-animator-scroll1.7.0
- npmtailwindcss-effector1.7.0
- npmts-await3.1.8
- npmtx-guard-snap1.0.0
- npmtypescript-base581.0.0
- npmwarp-dependency1.0.01.0.1
- npmwhs4_nmp1.0.01.0.1
- npmwhs4_npm1.0.0
- npmwhs4_npm_test1.0.01.0.11.0.21.0.3
- npmwhs4_pnm1.0.0
- npmwsh4_npm1.0.0
- npmwsh4-nmp1.0.0
- npmzod-pino4341.0.1271.0.128
- npmzod-pino4441.0.1281.0.1291.0.1301.0.131
- npmzredis-typed1.0.127
npm-2026-07-07-ghsa-malware-sweepSource advisory - npm@43uh3ig43/telemetry-client
- Critical7 Jul 202610 packages tracked
Coordinated npm + PyPI campaign typosquats Paysafe / Skrill / Neteller payment SDKs, exfiltrates keys to AWS
Socket detected a coordinated cross-registry campaign on 2026-07-07 12:56 UTC: 13 npm and 4 PyPI packages impersonating the Paysafe / Skrill / Neteller payment SDKs, exposing plausible legitimate APIs but shipping a credential-theft module that harvests
KEY/SECRET/TOKEN/PASS/AUTH/APIenv vars and Paysafe API keys and exfiltrates them to attacker-controlled AWS infrastructure. All npm versions unpublished ~2026-07-08 00:25 UTC.npmPyPIAffected packages12 packages · 39 versions
- npmpaysafe-api1.0.01.0.11.0.21.0.3
- PyPIpaysafe-api1.0.0
- npmpaysafe-cards1.0.01.0.11.0.21.0.3
- npmpaysafe-checkout1.0.01.0.11.0.21.0.3
- npmpaysafe-js1.0.01.0.11.0.21.0.3
- npmpaysafe-node1.0.01.0.11.0.21.0.3
- npmpaysafe-payments1.0.01.0.11.0.21.0.3
- PyPIpaysafe-payments1.0.0
- PyPIpaysafe-sdk1.0.0
- npmpaysafe-vault1.0.01.0.11.0.21.0.3
- npmskrill-payments1.0.01.0.11.0.21.0.3
- npmskrill-sdk1.0.01.0.11.0.21.0.3
multi-2026-07-07-paysafe-skrill-payment-sdk-typosquatSource advisory - npmpaysafe-api
- High6 Jul 2026162 packages tracked
GitHub Advisory malware sweep - ~155 npm packages (logger/tailwind/eslint/bignumber typosquats, polymarket-onchain-* crypto-drainers) taken down 2026-07-06
On 2026-07-06 GitHub's Advisory Database published ~155 CWE-506 Embedded Malicious Code advisories against npm packages - the largest single-day 2026 GHSA npm-malware sweep to date. The batch clusters into six naming families: chalk/pino/winston/
*-loggerpretty-print typosquats, tailwindcss/vite typosquats, eslint /*-lint-*helper squats, bignumber.js / crypto-math typosquats, chai*-as-*matcher squats, and twopolymarket-onchain-*crypto-drainer slugs continuing the June cluster. npm replaced every name with0.0.1-security.npmAffected packages162 packages · 429 versions
- npm@jaime9008/math-service1.0.01.0.11.0.2
- npmargonflux2.0.1
- npmawesome-cli-logger1.0.01.2.0
- npmbig-numer5.0.5
- npmbig-numerate5.0.3
- npmbig-numerator5.0.35.0.6
- npmbig256-ts5.0.35.0.4
- npmbigint.fs5.0.55.0.6
- npmbigint.os5.0.55.0.65.0.75.0.8
- npmbjs-biginteger5.0.55.0.6
- npmbjs-lint-builder1.0.5
- npmbjs-lint-builders1.0.41.0.51.1.0
- npmbn-eslint.js8.0.5
- npmbn-math1.0.01.0.1
- npmbootstrap-utils4.5.05.1.1
- npmbtd-smart1.0.21.0.3
- npmbubblestr1.1.4
- npmbytecore5.3.1
- npmchai-as-decrypted4.2.8
- npmchai-as-init1.4.51.4.61.4.77.0.6
- npmchai-as-polished7.0.8
- npmchai-dec2.3.5
- npmchai-guard1.0.01.2.3
- npmchain-await-test1.3.5
- npmchalk-logger-prettier1.0.11.0.21.0.31.0.41.0.51.0.71.0.8
- npmchalk-plus-ts1.0.31.0.4
- npmchalk-prettier1.0.81.0.9
- npmchalk-pro-logger1.1.11.1.2
- npmchalki-pretty1.0.0
- npmchalks-logger1.0.91.1.01.1.11.1.21.1.3
- npmcjs-biginteger5.0.35.0.55.0.6
- npmclassbreeze-utils0.7.70.7.80.7.90.7.10
- npmcolor-cli-log2.0.02.1.0
- npmcolor-logger-console3.1.83.1.9
- npmcompetion1.8.11.8.21.8.31.8.4
- npmcookie-ease1.0.01.0.51.0.61.0.71.0.81.0.91.1.11.1.21.1.31.1.5
- npmcustom-log-viewer1.0.0
- npmdb-query-log1.0.11.0.2
- npmdebug-glitzs1.0.01.0.11.0.21.0.31.0.4
- npmdevkit-scripts1.0.01.0.3
- npmdf-vision0.0.11.1.701.1.711.1.721.1.731.1.741.1.751.1.761.1.771.1.781.1.79
- npmdotenv-express2.5.517.4.217.4.317.4.417.4.517.4.6
- npmelevate-log2.0.5
- npmemojiprint-logger1.1.05.6.2
- npmemojiprint-prettier1.0.9
- npmenv-axios1.3.6
- npmenvironment-gate7.3.57.3.6
- npmes-lint-builders1.0.01.0.31.0.41.0.5
- npmes-lint-entry1.0.0
- npmeslint-helper4.0.14.0.2
- npmeslint-vite1.0.01.0.11.0.2
- npmeth-logger4.3.204.3.21
- npmeth-tick7.4.177.4.18
- npmether-bn.js1.0.01.0.31.1.11.2.11.3.11.3.31.3.41.4.01.4.1
- npmexpress-dotenv1.3.5
- npmexpress-guardrail1.3.51.4.1
- npmexpress-initial12.1.712.1.812.1.912.1.10
- npmexpress-session-js1.0.01.19.0
- npmfastnodemailer8.0.28.0.38.0.4
- npmgraphpilot0.1.00.1.10.1.20.1.30.1.41.0.0
- npmgrid-settings-align14.1.114.1.2
- npmhjs-biginteger5.0.5
- npmhjs-lint-builders1.0.4
- npmjs-crypto-promise1.0.1
- npmjs-unimode1.1.11.1.21.1.31.1.41.1.51.1.61.1.71.1.81.1.91.1.10
- npmjsontoken-extend1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.111.0.121.0.13
- npmjsonupper1.0.05.1.0
- npmlint-builders1.0.0
- npmlint-builds1.0.01.0.5
- npmlint-nule1.0.4
- npmlint-nuler1.0.4
- npmlint-null1.0.4
- npmlinter-entry1.0.0
- npmlog-format-thread1.0.01.0.1
- npmlog-upgrade7.1.0
- npmlogger-beauty1.0.11.0.21.0.31.1.02.1.1
- npmmetrica-chain2.4.5
- npmmetrica-node2.4.5
- npmmjs-biginteger5.0.55.0.6
- npmmodulyn1.0.1
- npmmongoose-json-format3.0.03.0.1
- npmmongoose-lean-hooks0.5.20.5.30.5.40.5.50.5.60.5.7
- npmmotion-lib2.3.5
- npmnext-bignumber.js1.0.0
- npmnode-env-detector1.0.01.0.1
- npmnodepathbalance541.1.0
- npmnormalize-path-seq3.8.9
- npmnpm-doc-dev1.0.41.0.51.0.61.0.71.0.81.0.91.1.01.1.1
- npmnpm-eslint-helper1.0.1
- npmolder_morgan1.0.11.0.2
- npmpeptideenv16.6.116.6.216.6.316.6.416.6.516.6.6
- npmpicocolor-logger1.0.01.0.11.0.2
- npmpino-formatter1.1.121.1.13
- npmpino-pretty-logs1.0.71.0.81.1.02.0.0
- npmpino-sdk-v29.9.0
- npmpino-utils1.3.61.4.0
- npmpolymarket-onchain-plugin2.1.32.1.42.1.5
- npmpolymarket-onchain-sdk1.0.21.0.31.0.4
- npmprettier-logger0.1.40.1.50.1.6
- npmpretty-pino-logger1.0.01.0.11.0.21.0.31.0.42.0.12.0.2
- npmpretty-pino-loggers1.0.1
- npmrandom-string-641.0.01.0.1
- npmreact-check-error2.1.62.1.7
- npmreact-native-template-my-starter1.0.0
- npmreact-next-dom1.0.01.1.717.2.717.2.8
- npmreact-svg-render1.0.2
- npmrenderctx1.1.1
- npmrequest-js-validator1.0.21.0.31.0.4
- npmrma-utils1.0.1
- npmrollup-plugin-polyfill-handler1.0.01.0.1
- npmrouter-kit0.1.10.1.20.1.30.1.40.1.50.1.60.1.70.2.00.2.10.2.20.2.30.2.51.0.01.0.11.0.21.0.31.2.01.2.11.2.21.2.31.2.41.2.51.2.61.3.01.3.11.3.21.3.31.3.42.0.02.0.12.1.0
- npmsafe-validate1.0.11.0.21.0.31.0.4
- npmsecure-box1.0.11.0.2
- npmset-proto-chain1.0.3
- npmsjs-biginteger5.0.55.0.6
- npmsjs-builder1.0.41.0.5
- npmsjs-builders1.0.4
- npmsjs-lint-build11.0.4
- npmsleek-pretty1.0.0
- npmsol-sdk2.3.18
- npmst-biginteger5.0.5
- npmst-bigintr5.0.55.0.6
- npmstacknova1.0.0
- npmstyled-text-logger1.3.1
- npmsubsearch1.0.21.0.3
- npmsyncora0.2.03.5.7
- npmtailstyle-core0.0.1
- npmtailwind-fonttype-inter2.3.2
- npmtailwind-scroller1.0.2
- npmtailwind-typography-plus2.1.0
- npmtailwindcss-animatecss-latest2.1.02.1.1
- npmtailwindcss-fonttype-inter2.3.12.3.2
- npmtailwindcss-fonttypo-inter2.3.2
- npmtailwindcss-framer-motion1.1.3
- npmtailwindcss-svg-helper1.17.91.18.0
- npmtest-prettier1.0.9
- npmtheta-connector1.0.0
- npmtheta-kit1.0.01.0.11.0.21.0.3
- npmts-bigtn1.3.11.3.2
- npmts-build-optimize1.1.51.1.61.2.01.2.11.2.2
- npmts-eslint-helper4.0.14.0.24.0.34.0.44.0.5
- npmts-eslinter1.0.0
- npmts-lint-builders1.0.5
- npmts-lint-builds1.0.5
- npmts-relayer-pub1.0.0
- npmts-webplug3.0.53.0.63.0.73.0.8
- npmtsliverhome1.0.01.1.11.1.21.1.31.1.41.1.5
- npmtwcompose-utils0.7.60.7.7
- npmtxs-data1.0.1
- npmtypedecode1.0.11.0.21.0.3
- npmunique-id-641.0.0
- npmvite-config-field1.1.01.1.11.1.21.1.31.1.41.1.5
- npmvite-plugin-compress-js0.5.40.5.50.5.60.5.7
- npmvite-plugin-svg-paths1.1.51.1.61.1.71.1.81.1.9
- npmweb-pool2.3.5
- npmwebpack-cache-clean0.1.4
- npmwebpack-patch1.1.71.1.81.1.91.2.0
- npmwime-zle1.1.4
- npmwindrule-utils0.0.1
- npmwinston-js-express1.0.01.0.31.0.41.0.51.0.61.0.71.1.11.1.2
- npmwinston-prism1.0.1
- npmxnder-sdk-js0.1.0
npm-2026-07-06-ghsa-malware-sweepSource advisory - npm@jaime9008/math-service
- High4 Jul 20265 packages tracked
paperclip2 / vps-maintenance postinstall reverse shell to 185.112.147.174:7007
On 2026-07-04 the OX Research team disclosed npm packages -
paperclip2,vps-maintenance,vps-maintenance-paperclip-adapter- published by usersrm0rganthat hide apostinstallreverse shell to185.112.147.174:7007insidepackage.json.paperclip2ships with no JavaScript files at all, defeating static scanners that only inspect.js. Two follow-on names -paperclip-host-utilsandvps-adapter-core- landed 2026-07-07 and joined the same GHSA takedown.npmAffected packages5 packages · 14 versions
- npmpaperclip-host-utils1.0.01.0.21.0.31.0.41.0.51.0.61.0.7
- npmpaperclip21.0.0
- npmvps-adapter-core1.0.01.0.11.0.2
- npmvps-maintenance0.1.0
- npmvps-maintenance-paperclip-adapter0.1.10.1.2
npm-2026-07-04-paperclip2-reverse-shellSource advisory - npmpaperclip-host-utils
- High3 Jul 202614 packages tracked
GitHub Advisory malware sweep - 14 npm packages (TypeScript/API util family, SQL/node-cloud scoped cluster, `@lodash-en` typosquat) taken down 2026-07-03
On 2026-07-03 GitHub's Advisory Database dropped 14 CWE-506 Embedded Malicious Code advisories against npm packages, all retired inside a ~30-minute window (15:36–16:06 UTC). The sweep spans three distinct micro-clusters: an unscoped
*-node-utils/*-api-*TypeScript/API-helper family (5 packages, 20+ versions), a SQL-and-cloud scoped cluster on personal namespaces (@sql-access/,@sqlite-node/,@sql-trigger/,@node-cloud/), and three miscellaneous typosquats including@lodash-en/lodash-en. npm replaced every name with0.0.1-security.npmAffected packages14 packages · 73 versions
- npm@antoncarlos1/nodelamp1.0.01.0.1
- npm@jacobtan/decode-sdk1.0.0
- npm@lodash-en/lodash-en1.4.111.5.0
- npm@node-cloud/create1.0.01.0.11.0.21.0.31.0.41.0.51.0.6
- npm@sql-access/nodesql1.0.01.0.31.0.51.0.61.0.71.0.81.0.91.1.01.1.11.1.21.1.31.1.41.1.51.1.61.1.71.1.81.1.9
- npm@sql-trigger/nodesql1.0.01.0.11.0.2
- npm@sqlite-node/createsql1.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.1.01.1.11.1.21.1.31.1.41.1.51.1.7
- npmalder_morrgan1.0.01.0.1
- npmapi-node-utils2.2.4
- npmapi-ts-utils1.0.02.1.32.1.43.2.13.2.23.4.73.4.83.4.93.5.9
- npmdecode-sdks1.0.01.0.11.0.21.0.3
- npmts-node-utils8.0.18.0.48.0.6
- npmtypescript-util-core3.5.07.1.37.1.57.1.6
- npmweb-api-node1.3.21.3.3
npm-2026-07-03-ghsa-malware-sweepSource advisory - npm@antoncarlos1/nodelamp
- Critical3 Jul 20266 packages tracked
JFrog: Lazarus / OtterCookie `rollup-*-polyfill-core` npm campaign - 6 packages steal AI-coder credentials, browser data and crypto wallets
JFrog Security Research disclosed a 6-package DPRK / Contagious Interview npm campaign that mimics the legitimate
rollup-plugin-polyfill-nodeproject down to its metadata. First-stage packages carry a base64-encodednpm installthat fetches an SVG-utility-shaped second stage; the second stage evaluates a payload pulled from JSONKeeper and steals credentials for AWS, Azure, Google Gemini, Anthropic Claude, Windsurf, Cursor, VS Code, SSH and Zsh, plus browser data and crypto wallets. Two of the first-stage packages are STILL live on npm as of 2026-07-04.npmAffected packages6 packages · 37 versions
- npmquirky-token1.0.01.0.11.0.2
- npmreact-icon-svgs1.0.01.0.11.0.22.15.3
- npmrollup-packages-polyfill-core0.0.00.5.00.12.30.13.00.13.10.13.20.13.30.13.40.13.50.13.60.13.70.13.8
- npmrollup-plugin-polyfill-connect1.0.11.0.21.0.3
- npmrollup-runtime-polyfill-core0.0.10.12.50.13.00.13.10.13.20.13.30.13.40.13.50.13.60.13.70.13.80.13.90.14.0
- npmswift-parse-stream1.0.01.0.2
npm-2026-07-03-jfrog-lazarus-rollup-polyfill-ottercookieSource advisory - npmquirky-token
- High2 Jul 20269 packages tracked
GitHub Advisory malware sweep - 9 npm packages (tailwind/animate typosquats, db-* cluster, `vitest-agent`) taken down 2026-07-02
On 2026-07-02 GitHub's Advisory Database dropped 9 CWE-506 Embedded Malicious Code advisories against npm packages published between 2026-05-24 and 2026-07-01. Three distinct micro-clusters were retired within minutes of each other: a Tailwind/animate typosquat trio (
animatecss-postcss-plugin,tailwind-animates,tailwind-typography-stylecss), adb-*/cache-*fake-utility quartet, and the standalonevitest-agentVitest typosquat plus one scoped React Native template. npm replaced every name with a0.0.1-securityholding tarball.npmAffected packages9 packages · 22 versions
- npm@modhamanish/rn-mm-template1.0.11.0.21.0.31.0.41.0.51.1.01.1.11.1.21.1.3
- npmanimatecss-postcss-plugin1.0.01.0.1
- npmcache-section-helper1.0.7
- npmdb-connector-log1.0.01.0.1
- npmdb-convertor1.0.5
- npmdb-plog1.0.01.0.1
- npmtailwind-animates1.0.1
- npmtailwind-typography-stylecss0.8.3
- npmvitest-agent1.0.01.0.51.0.6
npm-2026-07-02-ghsa-malware-sweepSource advisory - npm@modhamanish/rn-mm-template
- High1 Jul 20263 packages tracked
`clx-cookieparser` + `clx-cookie-signature` cookie-parser impersonators - DGA-driven RAT dropper cluster (GHSA dropped 2026-06-29, updated 2026-07-01)
clx-cookieparser(7 versions1.4.4–1.5.1) andclx-cookie-signature@1.2.1impersonate Express'scookie-parser/cookie-signature. Both hide a dropper that XOR-derives a C2 IP from key0x496AAC7E, then fetches andevalsstartup.js- no install hook, execution fires on first API call. GHSA-jpg2-3r22-63v7 / GHSA-vwwm-x6xj-cfmf, refreshed 2026-07-01.npmAffected packages3 packages · 14 versions
- npmclx-cookie-signature1.2.1
- npmclx-cookieparser1.4.41.4.51.4.61.4.71.4.81.4.91.5.1
- npmexpress-cookie-parser1.4.71.4.81.4.91.4.101.4.111.4.12
npm-2026-07-01-clx-cookie-dga-dropperSource advisory - npmclx-cookie-signature
- High1 Jul 20268 packages tracked
`@marketfront` dependency-confusion Wave 4 - 25 npm packages batch-published at `7.0.0` reuse the "Internal package - Platform Engineering Team" lure
On 2026-07-01 22:59 UTC the npm account
marketfrontcreated the@marketfrontscope and batch-published 25 e-commerce / marketing-frontend packages in a ~3-minute window, all at version7.0.0. Every package carries a postinstall credential-file harvester (~20 secret files including~/.ssh,~/.aws/credentials,~/.kube/config,~/.npmrc,~/.env) and the identical README lure "Internal package - Platform Engineering Team" - Wave 4 of the SafeDep-trackedoob.moika.techoperator lineage.npmAffected packages8 packages · 8 versions
- npm@marketfront/bannerpopup7.0.0
- npm@marketfront/customdealsfeed7.0.0
- npm@marketfront/designsystemdevtool7.0.0
- npm@marketfront/fashiononboardingpopup7.0.0
- npm@marketfront/footer7.0.0
- npm@marketfront/header7.0.0
- npm@marketfront/livestreampreviewpopup7.0.0
- npm@marketfront/navbar7.0.0
npm-2026-07-01-marketfront-dep-confusion-wave4Source advisory - npm@marketfront/bannerpopup
- High1 Jul 20264 packages tracked
ChocoPoC - trojanized CVE PoC repos deliver ChocoPoC RAT via malicious PyPI packages frint / skytext (Mapbox dataset dead-drop C2)
Joint Sekoia / YesWeHack disclosure on 2026-07-01: at least seven trojanized CVE proof-of-concept repositories on GitHub silently pull the malicious PyPI package
frint, which depends onskytext.skytextships a precompiled native extension (gradient.so/gradient.pyd) that deploys "ChocoPoC" - a Python RAT with shell/Python command execution, browser-credential theft, and Mapbox Dataset API dead-drop C2. Targets vulnerability researchers and pentesters cloning PoC repos. ~2,400 downloads ofskytextbefore takedown.PyPIAffected packages4 packages · 0 versions
- PyPIfrint
- PyPIlogcrypt.cryptography
- PyPIskytext
- PyPIslogsec
pypi-2026-07-01-chocopoc-frint-skytextSource advisory - High30 Jun 202618 packages tracked
GitHub Advisory malware sweep - 20+ npm packages (chai-as-*, brock-*, rebrandly-*, dep-confusion + typosquat batch) taken down 2026-06-30
On 2026-06-30 GitHub's Advisory Database dropped a coordinated batch of ~25 CWE-506 Embedded Malicious Code advisories against unrelated npm packages published between 2026-05-27 and 2026-06-30. The batch mixes at least four distinct sub-clusters:
chai-as-persisted/chai-as-assured(Chai typosquats),brock-loader/brock-react-alerts(with a9999.0.0dep-confusion tag), therebrandly-domains-*pair (both9999.0.0), and a wider fan-out of standalone malicious names.npmAffected packages18 packages · 43 versions
- npmagent-starter-pack0.0.1
- npmbrock-loader1.9.9
- npmbrock-react-alerts1.99.999999.0.0
- npmchai-as-assured6.0.47.1.2
- npmchai-as-persisted4.2.86.1.9
- npmconfluent-kafka-javascript0.0.1
- npmendpointmap2.1.03.0.0
- npmnbmolviz-js0.0.1
- npmpostcss-property-rollup0.0.1
- npmprocwire1.3.02.0.0
- npmquoting0.1.0
- npmrebrandly-domains-digger9999.0.0
- npmrebrandly-domains-search-client9999.0.0
- npmrs-biginteger6.1.36.1.5
- npmsetup-cicd0.0.1
- npmterminal-prettier1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.1.01.1.11.1.21.1.31.1.41.1.51.1.61.1.71.1.81.1.9
- npmts-lint-builders-v2.12.1.0
- npmts-linting-builder2.1.2
npm-2026-06-30-ghsa-malware-sweepSource advisory - npmagent-starter-pack
- High30 Jun 202621 packages tracked
GHSA-flagged malware brands - 16 autotel-*, 4 awaitly-*, and `ai-sdk-ollama` packages (Nov 2025–Jun 2026) marked embedded-malicious-code on 2026-06-29/30
GitHub's Advisory Database dropped CWE-506 (Embedded Malicious Code) records on 2026-06-29 and 2026-06-30 against 21 npm "brand" packages built up over months: the entire
autotel-*observability family (16 packages, 400+ versions), theawaitlypromise-utility family (4 packages, ~180 versions), and theai-sdk-ollamaVercel AI-SDK typosquat (55 versions). Every published version of every listed package is now classified as malware.npmAffected packages21 packages · 939 versions
- npmai-sdk-ollama0.1.00.2.00.3.00.4.00.5.00.5.10.5.20.5.30.5.40.5.50.6.00.6.10.6.20.7.00.8.00.8.10.9.00.10.00.10.10.11.00.12.00.13.00.13.11.0.01.0.11.0.21.1.01.1.12.0.02.0.12.1.02.2.02.2.13.0.03.0.13.1.03.1.13.2.03.3.03.4.03.5.03.6.03.7.03.7.13.8.03.8.13.8.23.8.33.8.43.8.53.8.63.8.73.8.84.0.04.0.0-beta.0
- npmautotel-backends2.0.12.1.02.2.02.2.12.2.22.2.32.2.42.2.52.2.62.3.02.3.12.4.02.4.12.5.02.5.12.6.02.7.02.7.12.7.22.8.02.8.12.8.22.8.32.8.42.9.02.9.12.10.02.11.02.11.12.11.22.11.32.11.42.12.02.12.12.12.22.12.32.12.42.12.52.12.62.12.72.12.82.12.92.12.102.12.132.12.142.12.152.12.162.12.172.12.182.12.192.12.202.12.212.12.222.12.232.12.242.12.252.12.262.12.272.12.282.12.292.12.302.12.312.12.322.12.332.12.342.12.352.12.36
- npmautotel-cli0.1.00.4.00.4.10.4.20.5.00.6.00.7.00.7.10.8.00.8.10.8.20.8.30.8.40.8.60.8.70.8.80.8.90.8.100.8.110.8.120.8.130.8.140.8.150.9.00.9.10.10.00.11.0
- npmautotel-drizzle0.0.10.0.20.0.30.0.40.0.50.0.60.0.70.0.80.0.90.0.100.0.110.0.140.0.150.0.160.0.170.0.180.0.190.0.200.0.210.0.220.0.230.0.240.0.250.0.260.0.270.0.280.0.290.0.300.0.310.0.320.0.330.0.340.0.350.0.360.0.37
- npmautotel-eventcatalog1.0.01.0.12.0.02.0.13.0.03.0.14.0.04.0.14.0.25.0.05.0.15.0.26.0.07.0.08.0.09.0.010.0.011.0.0
- npmautotel-hono0.1.00.1.10.1.20.2.00.3.00.3.10.3.20.3.30.3.40.4.00.4.10.4.20.4.30.4.40.4.50.4.60.4.70.4.80.4.90.4.100.4.130.4.140.4.150.4.160.4.170.4.180.4.190.4.200.4.210.4.220.4.230.4.240.4.250.4.260.4.270.4.280.4.290.4.300.4.310.4.320.4.330.4.340.4.350.4.36
- npmautotel-mcp0.1.10.1.20.1.30.1.40.1.70.1.80.1.90.1.100.1.110.1.120.1.130.1.140.1.150.1.162.0.02.0.13.0.03.0.14.0.04.0.15.0.05.0.16.0.06.0.17.0.07.0.18.0.08.0.19.0.09.0.110.0.010.0.111.0.011.0.113.0.013.0.114.0.014.0.115.0.015.0.115.0.216.0.016.0.117.0.017.0.117.0.218.0.018.0.119.0.019.0.120.0.020.0.121.0.021.1.021.1.122.0.022.0.123.0.023.0.124.0.024.0.125.0.025.0.126.0.026.0.126.0.227.0.027.0.128.0.028.0.128.0.228.0.329.0.029.0.1
- npmautotel-mcp-instrumentation29.0.029.0.129.0.230.0.030.0.330.0.430.0.531.0.031.0.132.0.032.0.133.0.033.0.133.0.234.0.034.0.134.0.235.0.036.0.037.0.038.0.039.0.040.0.0
- npmautotel-mongoose0.0.10.0.20.0.31.0.01.0.11.0.22.0.02.0.32.0.42.0.53.0.03.0.14.0.04.0.15.0.05.0.15.0.26.0.06.0.16.0.27.0.08.0.08.1.09.0.010.0.010.1.010.1.111.0.012.0.0
- npmautotel-pact0.2.00.2.10.2.21.0.01.0.11.0.21.0.31.0.42.0.03.0.04.0.05.0.06.0.07.0.07.0.17.0.2
- npmautotel-playwright0.1.00.2.00.2.10.3.00.4.00.4.10.4.20.4.30.4.40.4.50.4.60.4.70.4.80.4.90.4.100.4.110.4.120.4.130.4.140.4.150.4.160.4.190.4.200.4.210.4.220.4.230.4.240.4.250.4.260.4.270.4.280.4.290.4.300.4.310.4.320.4.330.4.340.4.350.4.360.4.370.4.380.4.390.4.400.4.410.4.42
- npmautotel-plugins0.4.00.5.00.6.00.6.10.6.20.6.30.6.40.6.50.6.60.7.00.7.10.8.00.8.10.9.00.9.10.10.00.11.00.11.10.11.20.12.00.12.10.13.00.14.00.14.10.15.00.15.10.16.00.17.00.18.00.18.10.18.20.18.30.19.00.19.10.19.20.19.30.19.40.19.50.19.60.19.70.19.80.19.90.19.100.19.130.19.140.19.150.19.160.19.170.19.180.19.190.19.200.19.210.19.220.19.230.19.240.19.250.19.260.19.270.19.280.19.290.19.300.19.310.19.320.19.330.19.340.19.350.19.36
- npmautotel-sentry0.1.00.1.10.1.20.2.00.3.00.4.00.4.10.4.20.4.30.5.00.5.10.5.20.5.30.5.40.5.50.5.60.5.70.5.80.5.100.5.110.5.120.5.130.5.140.5.150.5.160.5.17
- npmautotel-subscribers4.0.04.1.04.1.15.0.05.0.16.0.06.0.17.0.07.0.18.0.08.0.19.0.09.0.110.0.010.0.111.0.011.0.112.0.012.0.113.0.013.0.114.0.014.1.014.1.115.0.015.0.116.0.016.0.116.0.217.0.017.0.118.0.018.0.118.0.218.0.319.0.019.0.120.0.020.0.121.0.021.0.122.0.022.0.122.0.223.0.023.0.123.0.224.0.024.0.125.0.025.0.126.0.026.0.127.0.027.0.127.0.228.0.028.0.128.0.229.0.029.0.129.0.229.0.329.0.429.0.529.0.630.0.030.0.130.0.230.0.330.0.431.0.031.0.331.0.431.1.031.1.131.1.231.1.331.1.432.0.032.0.132.1.033.0.034.0.034.1.034.1.135.0.035.0.135.0.236.0.037.0.038.0.039.0.040.0.041.0.041.0.141.0.2
- npmautotel-tanstack1.1.01.2.01.2.11.4.01.4.11.4.21.5.01.5.11.6.01.7.01.7.11.7.21.8.01.8.11.8.21.8.31.8.41.9.01.9.11.10.01.11.01.12.01.12.11.12.21.12.31.13.01.13.11.13.21.13.31.13.41.13.51.13.61.13.71.13.81.13.91.13.101.13.111.13.141.13.151.13.161.13.171.13.181.13.191.13.201.13.211.13.221.13.231.13.241.13.251.13.261.13.271.13.281.13.291.13.301.13.311.13.321.13.331.13.341.13.351.13.361.13.371.13.38
- npmautotel-vitest0.1.00.2.00.3.00.3.10.3.20.3.30.3.40.3.50.4.00.4.10.4.20.4.30.4.40.4.50.4.60.4.70.4.80.4.90.4.100.4.130.4.140.4.150.4.160.4.170.4.180.4.190.4.200.4.210.4.220.4.230.4.240.4.250.4.260.4.270.4.280.4.290.4.300.4.310.4.320.4.330.4.340.4.350.4.36
- npmautotel-web1.1.01.2.01.4.01.4.11.5.01.6.01.6.11.7.01.7.11.8.01.9.01.10.01.10.11.11.01.11.11.11.21.11.51.11.61.12.01.12.11.12.21.12.31.12.41.12.5
- npmawaitly1.0.01.1.01.2.01.3.01.4.01.5.01.5.11.6.01.7.01.8.01.9.01.10.01.11.01.12.01.13.01.14.01.15.01.16.01.17.01.18.01.19.01.20.01.21.01.22.01.23.01.24.01.25.01.26.01.27.01.28.01.29.01.30.01.31.01.31.11.32.01.32.11.33.01.33.11.33.21.33.31.33.41.34.0
- npmawaitly-analyze0.10.10.11.00.12.00.12.10.12.20.13.00.14.00.14.10.15.00.16.00.17.00.18.00.19.00.20.00.21.00.22.00.22.10.23.00.23.10.23.20.23.40.24.00.24.10.24.20.24.30.25.00.25.11.0.01.1.01.1.12.0.02.0.13.0.03.0.14.0.04.0.15.0.05.0.16.0.06.0.17.0.07.0.18.0.08.0.1
- npmawaitly-libsql0.1.00.1.11.0.01.0.12.0.02.0.13.0.03.0.14.0.04.0.15.0.05.0.16.0.06.0.17.0.07.0.18.0.08.0.19.0.09.0.110.0.010.0.111.0.011.0.112.0.012.0.113.0.013.0.114.0.014.0.115.0.015.0.116.0.016.0.117.0.017.0.118.0.018.1.018.1.119.0.019.0.120.0.020.0.121.0.021.0.122.0.022.0.122.0.223.0.0
- npmawaitly-mongo0.1.00.1.11.0.01.0.12.0.02.0.13.0.03.0.14.0.04.0.15.0.05.0.16.0.06.0.17.0.07.0.18.0.08.0.19.0.09.1.09.1.110.0.010.0.111.0.011.0.112.0.012.0.113.0.013.0.114.0.014.0.115.0.015.0.116.0.016.0.117.0.017.0.118.0.018.0.119.0.019.1.019.1.120.0.020.0.121.0.021.0.122.0.022.0.123.0.023.0.123.0.224.0.0
npm-2026-06-30-autotel-awaitly-brand-takedownSource advisory - npmai-sdk-ollama
- High29 Jun 202610 packages tracked
Internal-scope dependency-confusion cluster (Deel, Webda, Citi, BSCom, TiVo, CSEO-HR, +) taken down 2026-06-29
Between 2026-04-27 and 2026-05-31, ten npm packages impersonating internal corporate scopes - Deel, Webda, Citi ICG, BSCom, TiVo, CSEO-HR, Concerns, Via City Tools, WM - were published at
99.9.1to win dependency-confusion resolution against the matching private mirrors. npm support unpublished the whole batch on 2026-06-29 between 16:46 and 16:52 UTC and replaced them with0.0.1-securityholders; GHSA records dropped the same day.npmAffected packages10 packages · 10 versions
- npm@bscom/styling99.9.1
- npm@citi-icg-171632/citicms-repo-component99.9.1
- npm@concerns/i18n99.9.1
- npm@cseo-hr/trpweb-shared99.9.1
- npm@deel-ui/animation99.9.1
- npm@webd-infra/query-designer-domain99.9.1
- npm@webda-infra-ui/static-images99.9.1
- npmtivo-codelib-a99.9.1
- npmvia-city-tools-m-particle99.9.1
- npmwm-mapper99.9.1
npm-2026-06-29-internal-scope-dep-confusion-clusterSource advisory - npm@bscom/styling
- High28 Jun 20263 packages tracked
`@thone33/core-utils` + `@thone33/analytics-injector` + `@thone33/react-helpers` - production-gated c2-stager loader fetched from a GitHub repo
On 2026-06-28 17:08–17:42 UTC the npm account
thone33(gptconta847@gmail.com) published three collaborating packages:@thone33/analytics-injector(1.0.0,1.0.1) that fetches attacker JavaScript fromraw.githubusercontent.com/Dennisfrr/c2-stager/main/the%20assessment.jsand passes the response directly toeval;@thone33/core-utils(1.0.0–1.0.5) that depends on@thone33/analytics-injector: ^1.0.0and conditionally activates it only whenNODE_ENV === 'production'; and the newly-catalogued sibling@thone33/react-helpers(1.0.0–1.0.4, backfilled by GHSA on 2026-07-27, GHSA-vxmg-ff8j-2552). All three security-replaced on 2026-07-27 01:29–01:30 UTC.npmAffected packages3 packages · 13 versions
- npm@thone33/analytics-injector1.0.01.0.1
- npm@thone33/core-utils1.0.01.0.11.0.21.0.31.0.41.0.5
- npm@thone33/react-helpers1.0.01.0.11.0.21.0.31.0.4
npm-2026-06-28-thone33-c2-stager-clusterSource advisory - npm@thone33/analytics-injector
- High27 Jun 20266 packages tracked
`chai-as-persisted` + `chai-as-assured` - jsonspack DPRK campaign restarts with chai-as-* typosquat install-time RCE dropper
On 2026-06-26 → 2026-06-28 the same DPRK-linked operator behind the March jsonspack npm campaign restarted with
chai-as-persistedandchai-as-assured- typosquats ofchai-as-promisedthat ship install-time RCE droppers. Four versions across the two packages were published with the samehello@jsonspack.comauthor bug URL, fetching attacker JavaScript fromipregionchecker.orgvianew Function.constructoron everynpm install.npmAffected packages6 packages · 15 versions
- npmchai-as-assured7.1.26.0.4
- npmchai-as-const1.4.51.4.61.4.7
- npmchai-as-persisted4.2.86.1.9
- npmchai-as-reddit7.0.27.0.37.0.4
- npmchai-as-thread7.0.8
- npmchai-leaf1.4.51.4.61.4.71.4.8
npm-2026-06-27-chai-as-persisted-jsonspackSource advisory - npmchai-as-assured
- High27 Jun 20262 packages tracked
`crossmint-wallets-sdk` + `@epsteinlovekids483/crossmint-wallets-sdk-pentest` - install-time wallet/credential exfil via Crossmint SDK impersonators
Between 2026-06-26 13:44 UTC and 2026-06-27 03:09 UTC the npm account
epsteinlovekids483published two impersonators of the legitimate@crossmint/wallets-sdk: a scoped@epsteinlovekids483/crossmint-wallets-sdk-pentest(8 rapid versions) that onrequire()exfiltrates AWS keys, SSH keys, npm tokens,gh auth token, and Solana keypairs to a127.0.0.1:8052/exfilloopback C2; and the unscopedcrossmint-wallets-sdk@1.0.0that firespreinstallandinstalllifecycle scripts to capture host identifiers and POST them to an attacker-controlled endpoint. Both are flagged by CIRCL as MAL-2026-6522 and MAL-2026-6545.npmAffected packages2 packages · 9 versions
- npm@epsteinlovekids483/crossmint-wallets-sdk-pentest1.0.0-pentest1.0.1-pentest1.0.2-pentest1.0.5-pentest1.0.7-pentest1.0.9-pentest1.0.11-pentest1.0.11
- npmcrossmint-wallets-sdk1.0.0
npm-2026-06-27-crossmint-wallets-sdk-impersonatorSource advisory - npm@epsteinlovekids483/crossmint-wallets-sdk-pentest
- Critical27 Jun 20263 packages tracked
`ts-einkle` + `ts-ankle` + `ts-einkle-slot` - crypto-wallet drainer / SSH backdoor / big.js typosquat cluster
Between 2026-06-26 and 2026-06-27 a single naming-cluster operator published three new malicious npm packages -
ts-einkle(5 versions),ts-einkle-slot(5 versions), andts-ankle(1 version). All three execute install-time payloads:ts-einkleis a full credential and crypto-wallet stealer exfiltrating todatasecure-service.vercel.app/api/v1;ts-anklerecursively walks the home directory for credential files and installs an SSH public key in~/.ssh/authorized_keys;ts-einkle-slottyposquatsbig.jsand shadow-loadsnode-sloton everyrequire(). npm-support replaced all three with0.0.1-securityholders on 2026-06-29.npmAffected packages3 packages · 10 versions
- npmts-ankle1.1.0
- npmts-einkle1.0.91.1.01.1.21.1.3
- npmts-einkle-slot0.0.80.0.90.1.00.1.10.1.2
npm-2026-06-27-ts-einkle-ankle-wallet-clusterSource advisory - npmts-ankle
- High27 Jun 20261 package tracked
`polymarket-clob-math` - Polymarket SDK impersonator with Vercel-hosted unsigned tarball loader
On 2026-06-27 17:20 UTC an operator published
polymarket-clob-math@1.0.4to npm - an impersonator of the legitimate@polymarket/clob-clientmath helper. Apostinstallscript fetches a JSON config from an unverified Vercel domain (PSM_PEER_URL), downloads and extracts an unpinned mutable tarball whose contents the operator can swap at will, and executes the resulting attacker JavaScript on the installer. Internal references (peer-math.js,syncSession) masquerade it as a benign dependency-sync mechanism. npm-support replaced1.0.4with a0.0.1-securityholder on 2026-06-29.npmAffected packages1 package · 1 version
- npmpolymarket-clob-math1.0.4
npm-2026-06-27-polymarket-clob-math-vercel-loaderSource advisory - npmpolymarket-clob-math
- High27 Jun 20262 packages tracked
`livekit-agents` (npm) + `skillspector` (PyPI) - coordinated multi-ecosystem typosquat exfiltrating to `livekit-agents.xyz`
Between 2026-06-27 and 2026-06-28 a single operator published a coordinated multi-ecosystem typosquat campaign exfiltrating to the lookalike domain
livekit-agents.xyz. Unscopedlivekit-agentson npm (10 versions, four of them flagged malicious) impersonates the LiveKit Agents SDK while beaconing host telemetry. The PyPI packageskillspector(8 versions) - an unauthorized fork of a legitimate Nvidia project - exfiltrates every CLI argument tohttps://livekit-agents.xyz/skillspector-telemetry. The shared lookalike domain ties both packages to the same operator.npmPyPIAffected packages2 packages · 12 versions
- npmlivekit-agents0.3.00.3.10.3.20.3.4
- PyPIskillspector0.0.10.0.20.0.30.0.42.3.72.3.82.3.92.3.10
multi-2026-06-27-livekit-agents-skillspector-typosquatSource advisory - npmlivekit-agents
- High26 Jun 20261 package tracked
`tw-style-utils` - SStar Agent cross-platform RAT delivered via Tailwind Typography typosquat
tw-style-utilsmasqueraded as a Tailwind CSS typography plugin (99% of its code copied from@tailwindcss/typography) while ~5KB of top-level IIFE downloader code installed SStar Agent, a Windows/macOS RAT with keyboard/clipboard hooks and exfiltration capability. Two versions (0.7.0,0.7.1) were live on npm from 2026-05-26 17:19 UTC; npm yanked the package and replacedlatestwith a0.0.1-securityholder on 2026-06-26 05:17 UTC, and GitHub publishedGHSA-75cr-ggc5-8h7gthe same day.npmAffected packages1 package · 2 versions
- npmtw-style-utils0.7.00.7.1
npm-2026-06-26-sstar-tw-style-utilsSource advisory - npmtw-style-utils
- High26 Jun 20264 packages tracked
npm typosquat sweep - `pump-stream-logger`, `pump-laserstream-parser`, `pino-zod`, `rollup-plugin-polyfill-connect` yanked
On 2026-06-26 npm yanked four malicious typosquat packages within hours of each other -
pump-stream-logger,pump-laserstream-parser, andpino-zodwere taken down within a 10-second window at 05:10 UTC, androllup-plugin-polyfill-connectfollowed at 12:16 UTC. All four are GHSA-classified as CWE-506 Embedded Malicious Code; the package names target the Helius Solana streaming SDK, the Pino logger family, the Zod validation library, and therollup-plugin-polyfill-nodeRollup plugin.npmAffected packages4 packages · 7 versions
- npmpino-zod1.0.1211.0.122
- npmpump-laserstream-parser2.0.0
- npmpump-stream-logger1.0.0
- npmrollup-plugin-polyfill-connect1.0.11.0.21.0.3
npm-2026-06-26-pump-pino-rollup-typosquat-sweepSource advisory - npmpino-zod
- High25 Jun 20261 package tracked
`@vpms/design-system` - internal-scope dependency-confusion with preinstall env-var exfil to Pipedream
On 2026-06-25 between 15:52 UTC and 17:14 UTC, an operator published four versions of
@vpms/design-system(0.1.3,1.0.0,1.0.1,1.1.2) as a dependency-confusion attack against the internal@vpmsscope. The preinstall script iteratesprocess.envand harvests every variable whose name containsSECRET,TOKEN,PASSWORD,KEY, orCREDENTIAL, along with hostname, username, and process details, then exfiltrates the payload to a hardcoded Pipedream webhook ateov0bmnid410yqf.m.pipedream.net. npm-support replaced all four versions with a0.0.1-securityholder on 2026-06-29.npmAffected packages1 package · 4 versions
- npm@vpms/design-system0.1.31.0.01.0.11.1.2
npm-2026-06-25-vpms-design-system-pipedreamSource advisory - npm@vpms/design-system
- Critical24 Jun 20261 package tracked
codfish/semantic-release-action - 16 tags retargeted to Miasma imposter commit
On 2026-06-24 at 15:39:06 UTC an attacker force-pushed two imposter commits to
codfish/semantic-release-actionand repointed 16 tags - including the floating majorsv2,v3,v4,v5- to them. Any workflow pinned by tag pulls 781,580 bytes of obfuscated JavaScript that searches GitHub commit-search for thethebeautifulsnadsoftimeMiasma dead-drop channel andeval()s any signed payload, exfiltratingGITHUB_TOKENandNPM_TOKENfrom release workflows.GitHub ActionsAffected packages1 package · 14 versions
- GitHub Actionscodfish/semantic-release-actionv2v2.2.1v3v3.0.0v3.1.0v3.2.0v3.3.0v3.4.0v3.5.0v4v4.0.0v4.0.1v5v5.0.0
github-actions-2026-06-24-codfish-semantic-release-action-hijackSource advisory - GitHub Actionscodfish/semantic-release-action
- Critical24 Jun 20262 packages tracked
Leo Platform / RStreams - czirker maintainer account hijacked, 20 npm packages backdoored in 3 seconds
On 2026-06-24 at 23:04:55 UTC an attacker used the compromised
czirkernpm maintainer account to publish malicious versions of 20 Leo Platform / RStreams packages in a sub-3-second automated burst. Each tarball ships a weaponisedbinding.gypthat hides anode-gypcommand-substitution payload - the same "Phantom Gyp" hook used in the 2026-06-01 Miasma@redhat-cloud-servicesworm - running a Bun-runtime credential stealer (the Shai-Hulud "Hades" payload) that exfiltrates AWS/GCP/Azure/Kubernetes/Vault/npm/PyPI/GitHub/1Password secrets via the victim's own GitHub token.npmAffected packages2 packages · 2 versions
- npmleo-logger1.0.8
- npmleo-sdk6.0.19
npm-2026-06-24-leo-platform-miasma-hadesSource advisory - npmleo-logger
- High22 Jun 20263 packages tracked
PostCSS lookalike npm typosquats deliver multi-stage Windows RAT (abdrizak / JFrog)
JFrog disclosed three malicious npm packages published by the
abdrizakaccount that masquerade aspostcss-selector-parsertooling. An AES-256-GCM-encrypted blob drops a PowerShell stager which fetches a Windows RAT fromnvidiadriver[.]net, persists via the registry, and beacons over encrypted HTTP to95.216.92.207:8080to steal Chrome credentials and run remote-shell / file-transfer commands.npmAffected packages3 packages · 33 versions
- npmaes-decode-runner-pro1.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.11
- npmpostcss-minify-selector0.1.20.1.30.1.40.1.50.1.60.1.70.1.80.1.90.1.100.1.112.0.12.0.2
- npmpostcss-minify-selector-parser1.0.111.0.121.0.131.0.141.0.151.0.161.0.171.0.182.0.12.0.2
npm-2026-06-22-postcss-rat-typosquat-jfrogSource advisory - npmaes-decode-runner-pro
- High18 Jun 20268 packages tracked
`parket-helper` / `ts-ecro` big.js typosquat dropper cluster
A cluster of npm typosquats impersonating
big.jsshipped verbatim copies of the legitimate library with a single added five-line require ofparket-helper/parket-slot/new-solt- three otherwise-empty utility packages whose entire purpose is to execute attacker-controlled JavaScript at import time. GitHub and npm flagged the eight packages and replaced them with0.0.1-securityholders between 2026-06-18 and 2026-06-19.npmAffected packages8 packages · 16 versions
- npmnew-ecro0.0.60.0.70.0.9
- npmnew-solt0.0.70.0.80.0.9
- npmparket-helper0.0.15.8.1
- npmparket-slot0.0.6
- npmts-big-ecro0.1.03.8.1
- npmts-ecro0.0.50.0.6
- npmts-ecro-helper0.0.15.8.0
- npmts-esys0.0.5
npm-2026-06-18-parket-ecro-bigjs-typosquat-dropperSource advisory - npmnew-ecro
- Critical18 Jun 20263 packages tracked
`node-ci-utils` / `win-env-setup` / `macos-ci-utils` npm droppers deliver the NastyC2 Rust post-exploitation framework
Three npm packages -
node-ci-utils@2.1.4,win-env-setup@3.0.5/3.0.6, andmacos-ci-utils@1.0.0/1.0.1- masqueraded as CI tooling while acting as cross-platform droppers for NastyC2, a previously undocumented Rust post-exploitation framework with 80+ commands comparable in scope to Cobalt Strike and Sliver. npm removed all three packages between 2026-06-01 and 2026-06-13; the public disclosure landed in The Hacker News ThreatsDay Bulletin on 2026-06-18.npmAffected packages3 packages · 5 versions
- npmmacos-ci-utils1.0.01.0.1
- npmnode-ci-utils2.1.4
- npmwin-env-setup3.0.53.0.6
npm-2026-06-18-nastyc2-rust-implant-droppersSource advisory - npmmacos-ci-utils
- Critical17 Jun 202617 packages tracked
Mastra AI npm scope takeover via `easy-day-js` typosquat dropper
On 2026-06-17 between ~01:12 and 02:36 UTC, the dormant
ehinderocontributor account - never revoked from the@mastrascope - was used to mass-publish ~144 trojanised@mastra/*releases plusmastraandcreate-mastra, each declaring a neweasy-day-jsdependency whosepostinstallhook drops a cross-platform crypto-wallet stealer / RAT. Microsoft attributes the activity to Sapphire Sleet (BlueNoroff) with high confidence; combined exposure ~1.1M weekly downloads.npmAffected packages17 packages · 17 versions
- npm@mastra/agent-browser0.3.2
- npm@mastra/auth1.0.3
- npm@mastra/core1.42.1
- npm@mastra/evals1.3.1
- npm@mastra/github-signals0.1.2
- npm@mastra/loggers1.1.3
- npm@mastra/mem00.1.14
- npm@mastra/memory1.20.4
- npm@mastra/node-audio0.1.8
- npm@mastra/node-speaker0.1.1
- npm@mastra/rag2.2.2
- npm@mastra/react1.0.1
- npm@mastra/schema-compat1.2.12
- npm@mastra/voice-playai0.12.2
- npmcreate-mastra1.13.1
- npmeasy-day-js1.11.22
- npmmastra1.13.1
npm-2026-06-17-mastra-easy-day-jsSource advisory - npm@mastra/agent-browser
- Info16 Jun 20261 package tracked
`shai_hulululud`: first documented anti-AI-scanner protestware npm package
Socket flagged
shai_hulululud@1.0.48596(~9.3 MBindex.js, published 2026-06-16 by npm userptchli_knldg) - protestware whose only purpose is to probe and disrupt AI-based malware scanners. The tarball is a single JS file containing millions of repeated comments with prompt-injection content, fake system-override instructions, and context-flooding tokens. Runtime is inert; the payload is the source code itself, weaponised against any LLM-based scanner that ingests it.npmAffected packages1 package · 1 version
- npmshai_hulululud1.0.48596
npm-2026-06-16-shai-hulululud-ai-scanner-protestwareSource advisory - npmshai_hulululud
- Critical13 Jun 202611 packages tracked
Cyfirma multi-stage crypto-wallet campaign: moralis-sdk, ethers-jss, coinbase-wallet-utils, plus the `ethcompat` ethereum-C2 cluster
Cyfirma Research disclosed an 11-package npm campaign targeting Web3 / blockchain developers across three clusters: a YouTube-page-gated postinstall trojan in
moralis-sdk(2.7M+ downloads from the legitimate package name), theethers-jss/coinbase-wallet-utilsprivate-key sweepers (both yanked 2026-06-10), three long-lived typosquats (ganach,solidty,stelar-sdk, live since 2024), and theethcompat5-pack (hardhat-deploy-utils,web3-deploy-helper,defi-sdk-core,ethers-compat,ethereum-dev-utils) that AES-256-GCM-encrypts stolen creds and embeds them in Ethereum transactions to an attacker wallet.npmAffected packages11 packages · 12 versions
- npmcoinbase-wallet-utils1.0.0
- npmdefi-sdk-core1.0.0
- npmethereum-dev-utils1.0.0
- npmethers-compat1.0.0
- npmethers-jss6.13.1
- npmganach7.9.2
- npmhardhat-deploy-utils1.0.0
- npmmoralis-sdk1.0.01.0.1
- npmsolidty0.0.1
- npmstelar-sdk12.3.0
- npmweb3-deploy-helper1.0.0
npm-2026-06-13-cyfirma-moralis-ethcompat-clusterSource advisory - npmcoinbase-wallet-utils
- Critical12 Jun 20267 packages tracked
Solana FakeFix: JFrog flags 25 npm + PyPI packages stealing Solana keypairs and dev secrets to Telegram
JFrog Security Research disclosed
Solana FakeFix, a 25-package npm/PyPI campaign with two clusters: ~20 Solana typosquats / "stable-build" forks (solana-web3-stable,solana-rpc-client, …) promoted via GitHub issue spam by thePassWord1337account, and a 5-package CMS-themed Windows loader cluster (cms-storehub,cms-helpgit,cms-github,to-cms,shopifyto-cms). All variants exfiltrate Solana keypairs, SSH keys, cloud creds, and.envsecrets to a Telegram bot.npmAffected packages7 packages · 23 versions
- npmcms-github4.2.4
- npmcms-helpgit4.2.24.2.44.2.54.2.64.2.74.2.84.2.9
- npmcms-storehub1.2.71.2.81.2.91.3.01.3.11.3.21.3.31.3.41.3.51.3.6
- npmshopifyto-cms3.0.2
- npmsolana-rpc-client1.0.0
- npmsolana-web3-stable1.0.0
- npmto-cms1.0.01.0.1
multi-2026-06-12-solana-fakefix-jfrogSource advisory - npmcms-github
- Critical11 Jun 20264 packages tracked
Atomic Arch: 400+ AUR packages hijacked to ship npm-delivered Rust stealer with eBPF rootkit
Sonatype-2026-003775 (2026-06-11) - attackers hijacked 400+ orphaned Arch User Repository packages and rewrote their PKGBUILDs to pull three malicious npm dependencies (
atomic-lockfile@1.4.2,js-digest@4.2.2,lockfile-js@1.4.2). Each drops a Rust ELF credential stealer, loads an eBPF rootkit hiding processes/files/sockets when run as root, persists via systemd, and exfiltrates over Tor onion C2.npmAffected packages4 packages · 4 versions
- npmatomic-lockfile1.4.2
- npmjs-digest4.2.2
- npmlockfile-js1.4.2
- npmnextfile-js1.4.2
npm-2026-06-11-atomic-arch-aur-hijackSource advisory - npmatomic-lockfile
- Critical9 Jun 20261 package tracked
dbmux maintainer-account takeover: four backdoored versions seeded across two release branches
Between 2026-06-04 and 2026-06-05 the
dbmuxnpm maintainer account (bhagyamudgal) was hijacked and four backdoored releases were pushed across both the legacy1.xand current2.xbranches:1.0.5,1.0.6,2.2.4,2.2.5. GHSA-62wx-5f55-w8g2 (published 2026-06-09) classifies all four as CWE-506 embedded malicious code: any host that installed or executed them should be treated as fully compromised. npm deprecated every malicious release; the clean latest is2.2.3.npmAffected packages1 package · 4 versions
- npmdbmux1.0.51.0.62.2.42.2.5
npm-2026-06-09-dbmux-maintainer-takeoverSource advisory - npmdbmux
- Critical9 Jun 20264 packages tracked
SeedSweep: 10-package npm crypto-wallet drainer published by `aicrypto-xzggg`
On 2026-06-09 between 03:23 and 03:57 UTC the brand-new npm account
aicrypto-xzggg(vipsyria88@gmail.com) shipped 10 Web3-flavoured packages -wallet-sdk-9,swap-sdk-87,defi-tools-39,farming-tools-12, and six others - each carrying an identicalpostinstallpayload that reads wallet keystores, seed-phrase files, SSH keys, and.envfiles across six chains and exfiltrates them to Telegram bot id8227918239. npm unpublished every release ~8 hours later. Disclosed by Xygeni as the SeedSweep campaign.npmAffected packages4 packages · 4 versions
- npmdefi-tools-394.26.29
- npmfarming-tools-124.68.54
- npmswap-sdk-874.63.78
- npmwallet-sdk-93.7.73
npm-2026-06-09-seedsweep-aicrypto-xzgggSource advisory - npmdefi-tools-39
- Critical5 Jun 202634 packages tracked
Hades / Shai-Hulud PyPI wave: bioinformatics, MCP typosquats, and the .pth + Bun startup payload
Between 2026-06-05 and 2026-06-08 the Shai-Hulud / Miasma operator hopped to PyPI as "Hades", trojanising ~33 packages across the
nanguagebioinformatics cluster (StepSecurity: 19 quarantined projects), monarch-initiative phenotype tooling, and MCP/Flask typosquats. Each ships a*-setup.pthstartup hook → Bun credential stealer with cross-platform memory scraping.PyPIAffected packages34 packages · 56 versions
- PyPIbramin0.0.20.0.30.0.4
- PyPIcmd2func0.2.20.2.3
- PyPIcoolbox0.4.10.4.2
- PyPIdynamo-release1.5.4
- PyPIembiggen0.11.97
- PyPIensmallen0.8.101
- PyPIexecutor-engine0.3.40.3.5
- PyPIexecutor-http0.1.30.1.4
- PyPIfuncdesc0.2.20.2.3
- PyPIgpsea0.9.14
- PyPIlangchain-core-mcp1.4.21.4.3
- PyPImagique0.6.80.6.9
- PyPImagique-ai0.4.40.4.5
- PyPImflux-streamlit0.0.30.0.4
- PyPImrbios0.1.10.1.2
- PyPInapari-ufish0.0.20.0.3
- PyPInhmpy0.0.1
- PyPInucbox0.1.20.1.3
- PyPIokite0.0.70.0.8
- PyPIopenai-mcp2.41.12.41.2
- PyPIpantheon-agents0.6.10.6.2
- PyPIpantheon-toolsets0.5.50.5.6
- PyPIphenopacket-store-toolkit0.1.7
- PyPIppkt2synergy0.1.1
- PyPIpyphetools0.9.120
- PyPIray-mcp-server0.2.1
- PyPIrlask0.0.1
- PyPIrsquests0.0.1
- PyPIspateo-release1.1.2
- PyPIsynago0.1.10.1.2
- PyPItiktoken-mcp0.13.10.13.2
- PyPItlask0.0.1
- PyPIufish0.1.20.1.3
- PyPIuprobe0.1.30.1.4
pypi-2026-06-05-hades-shai-hulud-pypi-waveSource advisory - PyPIbramin
- Critical4 Jun 20264 packages tracked
IronWorm: Rust-built npm worm with eBPF rootkit and Tor C2 hits 36+ Arweave/WeaveDB packages
JFrog disclosed on 2026-06-04 that a single compromised npm account (
asteroiddao, tied to Arweave/WeaveDB maintainerocrybit) was used to push malicious versions of 36+ packages carrying IronWorm - a Rust ELF infostealer that loads an eBPF rootkit, exfiltrates over Tor, harvests Exodus crypto wallets, and republishes itself via stolen npm OIDC trust.npmAffected packages4 packages · 4 versions
- npmarnext0.1.5
- npmatomic-notes0.5.3
- npmroidjs0.1.7
- npmweavedb-lite0.1.1
npm-2026-06-04-ironworm-arweave-weavedbSource advisory - npmarnext
- Critical3 Jun 202626 packages tracked
Phantom Gyp Miasma worm hits @vapi-ai/server-sdk and the jagreehal portfolio via binding.gyp
Between 23:30 UTC on 2026-06-03 and ~01:30 UTC on 2026-06-04 the Miasma worm published a malicious 157-byte
binding.gyppayload through 57 npm packages and 286+ versions, starting at@vapi-ai/server-sdk(~408k weekly downloads) and cascading across the jagreehal maintainer'sautotel-*,awaitly-*,ai-sdk-*,executable-stories-*,node-env-resolver-*, andwrangler-deployportfolio. GitHub Advisories backfilled the full affected-version set across theautotel-*family and the widerawaitly-*portfolio on 2026-06-29 / 2026-06-30 (16 newautotel-*GHSAs plus expandedawaitly/awaitly-mongo/awaitly-libsql/awaitly-analyzeranges).npmAffected packages26 packages · 164 versions
- npm@vapi-ai/server-sdk0.11.1
- npmai-sdk-ollama0.13.11.1.12.2.13.8.5
- npmautotel-backends2.12.26
- npmautotel-cli0.8.14
- npmautotel-drizzle0.0.27
- npmautotel-eventcatalog1.0.12.0.13.0.14.0.25.0.1
- npmautotel-hono0.4.26
- npmautotel-mcp0.1.142.0.13.0.14.0.15.0.16.0.17.0.18.0.19.0.110.0.111.0.113.0.114.0.115.0.216.0.117.0.218.0.119.0.120.0.121.1.122.0.123.0.124.0.125.0.126.0.227.0.128.0.329.0.1
- npmautotel-mcp-instrumentation29.0.230.0.531.0.132.0.133.0.234.0.1
- npmautotel-mongoose0.0.31.0.22.0.53.0.14.0.15.0.26.0.1
- npmautotel-pact0.2.21.0.3
- npmautotel-playwright0.4.32
- npmautotel-plugins0.19.26
- npmautotel-sentry0.5.13
- npmautotel-subscribers4.1.15.0.16.0.17.0.18.0.19.0.110.0.111.0.112.0.113.0.114.1.115.0.116.0.217.0.118.0.319.0.120.0.121.0.122.0.223.0.224.0.125.0.126.0.127.0.228.0.229.0.630.0.431.1.4
- npmautotel-tanstack1.13.27
- npmautotel-vitest0.4.26
- npmautotel-web1.12.2
- npmawaitly1.33.3
- npmawaitly-analyze0.24.21.1.12.0.13.0.14.0.15.0.16.0.17.0.18.0.1
- npmawaitly-libsql0.1.11.0.12.0.13.0.14.0.15.0.16.0.17.0.18.0.19.0.110.0.111.0.112.0.113.0.114.0.115.0.116.0.117.0.118.1.119.0.120.0.121.0.122.0.1
- npmawaitly-mongo0.1.11.0.12.0.13.0.14.0.15.0.16.0.17.0.18.0.19.1.110.0.111.0.112.0.113.0.114.0.115.0.116.0.117.0.118.0.119.1.120.0.121.0.122.0.123.0.1
- npmawaitly-postgres0.1.11.0.12.0.13.0.24.0.15.0.16.0.17.0.18.0.19.0.110.0.111.0.112.0.1
- npmawaitly-visualizer1.0.1
- npmnode-env-resolver6.5.1
- npmwrangler-deploy1.5.5
npm-2026-06-03-phantom-gyp-vapi-jagreehalSource advisory - npm@vapi-ai/server-sdk
- High3 Jun 20262 packages tracked
@sentry-internals / @sentry-browser-sdk profiling-node typosquat via forged Sentry events
On 2026-06-03 Nutrient (PSPDFKit) caught a novel two-stage attack: an attacker submitted forged Sentry events through a public browser DSN, displaying "remediation" runbook text that instructed responders (and AI agents) to run
npx @sentry-internals/profiling-node --diagnose. The typosquat - and its sibling@sentry-browser-sdk/profiling-node(v1.0.0–1.0.5) - exfiltrated env, working-directory, and dev-context data toadvisory-tracker.combefore npm replaced both with0.0.1-securityholders.npmAffected packages2 packages · 7 versions
- npm@sentry-browser-sdk/profiling-node1.0.01.0.11.0.21.0.31.0.41.0.5
- npm@sentry-internals/profiling-node1.0.0
npm-2026-06-03-sentry-profiling-typosquatSource advisory - npm@sentry-browser-sdk/profiling-node
- High2 Jun 20261 package tracked
codexui-android exfiltrates OpenAI Codex refresh tokens for ~7 weeks before Aikido disclosure
Aikido disclosed on 2026-06-02 that every
codexui-androidnpm version from0.1.82(2026-04-13) through0.1.125silently exfiltrates the user's OpenAI Codexauth.json- access, refresh, and ID tokens - tosentry.anyclaw[.]store/startlog. The malicious code never appeared in the package's GitHub repository, and a companion Android app (50k+ installs) ships the same stealer.npmAffected packages1 package · 41 versions
- npmcodexui-android0.1.820.1.830.1.850.1.880.1.890.1.900.1.910.1.920.1.930.1.940.1.950.1.960.1.970.1.980.1.990.1.1000.1.1010.1.1020.1.1030.1.1040.1.1050.1.1060.1.1070.1.1080.1.1090.1.1100.1.1110.1.1120.1.1130.1.1140.1.1150.1.1160.1.1170.1.1180.1.1190.1.1200.1.1210.1.1220.1.1230.1.1240.1.125
npm-2026-06-02-codexui-android-openclawSource advisory - npmcodexui-android
- Critical1 Jun 202632 packages tracked
Miasma: @redhat-cloud-services Mini Shai-Hulud worm compromises 32 npm packages in 72 seconds
On 2026-06-01 an attacker published malicious versions of 32
@redhat-cloud-services/*npm packages in a 72-second window. The "Miasma" payload - a reskinned Mini Shai-Hulud worm - drops a preinstall script that runs a Bun-loaded credential stealer, harvests AWS/GCP/Azure/Kubernetes/Vault/GitHub/npm tokens, and exfiltrates to attacker-controlled GitHub repos taggedMiasma: The Spreading Blight.npmAffected packages32 packages · 95 versions
- npm@redhat-cloud-services/chrome2.3.12.3.22.3.4
- npm@redhat-cloud-services/compliance-client4.0.34.0.44.0.6
- npm@redhat-cloud-services/config-manager-client5.0.45.0.55.0.7
- npm@redhat-cloud-services/entitlements-client4.0.114.0.124.0.14
- npm@redhat-cloud-services/eslint-config-redhat-cloud-services3.2.13.2.23.2.4
- npm@redhat-cloud-services/frontend-components7.7.27.7.37.7.5
- npm@redhat-cloud-services/frontend-components-advisor-components3.8.23.8.43.8.6
- npm@redhat-cloud-services/frontend-components-config6.11.36.11.46.11.6
- npm@redhat-cloud-services/frontend-components-config-utilities4.11.24.11.34.11.5
- npm@redhat-cloud-services/frontend-components-notifications6.9.26.9.36.9.5
- npm@redhat-cloud-services/frontend-components-remediations4.9.24.9.34.9.5
- npm@redhat-cloud-services/frontend-components-testing1.2.11.2.21.2.4
- npm@redhat-cloud-services/frontend-components-translations4.4.14.4.24.4.4
- npm@redhat-cloud-services/frontend-components-utilities7.4.17.4.27.4.4
- npm@redhat-cloud-services/hcc-feo-mcp0.3.10.3.20.3.4
- npm@redhat-cloud-services/hcc-kessel-mcp0.3.10.3.20.3.4
- npm@redhat-cloud-services/hcc-pf-mcp0.6.10.6.20.6.4
- npm@redhat-cloud-services/host-inventory-client5.0.35.0.45.0.6
- npm@redhat-cloud-services/insights-client4.0.44.0.54.0.7
- npm@redhat-cloud-services/integrations-client6.0.46.0.56.0.7
- npm@redhat-cloud-services/javascript-clients-shared2.0.82.0.92.0.11
- npm@redhat-cloud-services/notifications-client6.1.46.1.56.1.7
- npm@redhat-cloud-services/patch-client4.0.44.0.54.0.7
- npm@redhat-cloud-services/quickstarts-client4.0.114.0.124.0.14
- npm@redhat-cloud-services/rbac-client9.0.39.0.49.0.6
- npm@redhat-cloud-services/remediations-client4.0.44.0.54.0.7
- npm@redhat-cloud-services/rule-components4.7.24.7.34.7.5
- npm@redhat-cloud-services/sources-client3.0.103.0.113.0.13
- npm@redhat-cloud-services/topological-inventory-client3.0.103.0.113.0.13
- npm@redhat-cloud-services/tsc-transform-imports1.2.21.2.41.2.6
- npm@redhat-cloud-services/types3.6.13.6.23.6.4
- npm@redhat-cloud-services/vulnerabilities-client2.1.92.1.11
npm-2026-06-01-miasma-redhat-cloud-servicesSource advisory - npm@redhat-cloud-services/chrome
- High28 May 202645 packages tracked
oob.moika.tech dependency-confusion campaign across nine npm scopes (mr.4nd3r50n / ce-rwb / t-in-one)
Between 2026-05-28 18:47 UTC and 2026-05-29 09:02 UTC a single operator using the npm aliases
mr.4nd3r50n,ce-rwb, andt-in-onepushed dependency-confusion packages across nine corporate-looking scopes (@cloudplatform-single-spa,@t-in-one,@ce-rwb,@wb-track,@data-science,@payments-widget,@travel-autotests,@capibar.chat,@sber-ecom-core). Postinstall stagers exfiltrateprocess.envtooob.moika[.]techwith a sharedX-Secretheader.npmAffected packages45 packages · 47 versions
- npm@capibar.chat/ui-kit99.0.799.5.7
- npm@ce-rwb/ce-tools-editor-admin3.5.22
- npm@ce-rwb/ce-tools-editor-core3.5.22
- npm@ce-rwb/ce-tools-editor-render3.5.22
- npm@cloudplatform-single-spa/administration100.100.100
- npm@cloudplatform-single-spa/arenadata-db100.100.100
- npm@cloudplatform-single-spa/base-static-page100.100.100
- npm@cloudplatform-single-spa/business-solutions100.100.100
- npm@cloudplatform-single-spa/cloud-dns100.100.100
- npm@cloudplatform-single-spa/cnapp-ui100.100.100
- npm@cloudplatform-single-spa/cp-api-gw100.100.100
- npm@cloudplatform-single-spa/datagrid100.100.100
- npm@cloudplatform-single-spa/dataplatform100.100.100
- npm@cloudplatform-single-spa/dataplatform-metastore100.100.100
- npm@cloudplatform-single-spa/dataplatform-trino100.100.100
- npm@cloudplatform-single-spa/employees100.100.100
- npm@cloudplatform-single-spa/enterprise100.100.100
- npm@cloudplatform-single-spa/floating-ips100.100.100
- npm@cloudplatform-single-spa/logaas100.100.100
- npm@cloudplatform-single-spa/marketplace-gigachat100.100.100
- npm@cloudplatform-single-spa/ml-ai-agents-agent100.100.100
- npm@cloudplatform-single-spa/ml-ai-agents-agent-system100.100.100
- npm@cloudplatform-single-spa/monitoring100.100.100
- npm@cloudplatform-single-spa/security-groups100.100.100
- npm@cloudplatform-single-spa/ssh-keys100.100.100
- npm@cloudplatform-single-spa/support100.100.100
- npm@cloudplatform-single-spa/svp-baas100.100.100
- npm@cloudplatform-single-spa/svp-interfaces100.100.100
- npm@cloudplatform-single-spa/svp-s3-storage100.100.100
- npm@cloudplatform-single-spa/vpn100.100.100
- npm@data-science/llm3.5.22
- npm@payments-widget/payments-widget-sdk3.5.22
- npm@sber-ecom-core/sberpay-widget99.0.799.5.8
- npm@t-in-one/add_app_middleware_token5.7.1
- npm@t-in-one/add_application5.7.1
- npm@t-in-one/add_application_service_token5.7.1
- npm@t-in-one/add_application_tid5.7.1
- npm@t-in-one/application_id_storage_key_token5.7.1
- npm@t-in-one/form_product_token5.7.1
- npm@t-in-one/get_application_hid5.7.1
- npm@t-in-one/only_difference_payload5.7.1
- npm@t-in-one/prefill_bundle_data_token5.7.1
- npm@t-in-one/prefill_credit_data_token5.7.1
- npm@travel-autotests/npm-proto3.5.22
- npm@wb-track/shared-front3.5.22
npm-2026-05-28-moika-dependency-confusionSource advisory - npm@capibar.chat/ui-kit
- High28 May 202614 packages tracked
vpmdhaj OpenSearch / ElasticSearch / DevOps typosquat burst (14 npm packages, Bun stager → cloud + CI/CD secret theft)
Microsoft Threat Intelligence flagged 14 typosquat npm packages published on 2026-05-28 by a single new maintainer alias
vpmdhaj(a39155771@gmail.com) in a ~4-hour window. Install-time stager pulls a ~195KB Bun-compiled credential harvester fromaab.sportsontheweb[.]net/x.php(X-Supply: 1header) and exfiltrates AWS, HashiCorp Vault, GitHub Actions and npm publish tokens.npmAffected packages14 packages · 41 versions
- npm@vpmdhaj/devops-tools1.0.7267
- npm@vpmdhaj/elastic-helper1.0.7269
- npm@vpmdhaj/opensearch-setup1.0.7267
- npm@vpmdhaj/search-setup1.0.7268
- npmapp-config-utility1.0.92001.0.9300
- npmelastic-opensearch-helper1.0.72651.0.91031.0.91041.0.91051.0.91061.0.91071.0.9108
- npmenv-config-manager2.1.9201
- npmopensearch-config-utility1.0.72651.0.91041.0.91051.0.9106
- npmopensearch-security-scanner1.0.81.0.91.0.10
- npmopensearch-setup1.0.90001.0.91001.0.91011.0.91021.0.9103
- npmopensearch-setup-tool1.0.72651.0.91061.0.91071.0.9108
- npmsearch-cluster-setup1.0.72651.0.91021.0.91031.0.9104
- npmsearch-engine-setup1.0.72651.0.91051.0.91061.0.91071.0.9108
- npmvpmdhaj-opensearch-setup1.0.91011.0.9102
npm-2026-05-28-vpmdhaj-opensearch-typosquatsSource advisory - npm@vpmdhaj/devops-tools
- High26 May 20261 package tracked
mouse5212-super-formatter: AI-generated npm infostealer targets Claude AI /mnt/user-data
On 2026-05-26 a fresh npm publisher pushed five versions of
mouse5212-super-formatter(1.0.0–1.0.4) that exfiltrate files from Claude AI's/mnt/user-datadirectory to an attacker GitHub repo via a hard-coded PAT. Disclosed by OX Security on 2026-05-27 ("Malware-Slop"); ~676 downloads before npm unpublished all versions.npmAffected packages1 package · 5 versions
- npmmouse5212-super-formatter1.0.01.0.11.0.21.0.31.0.4
npm-2026-05-26-mouse5212-claude-ai-exfilSource advisory - npmmouse5212-super-formatter
- Critical22 May 20264 packages tracked
Laravel-Lang Composer packages - every git tag retargeted to a malicious fork commit
On 2026-05-22 an attacker with push access to the
laravel-langGitHub org retargeted every git tag inlaravel-lang/lang,http-statuses,actions, andattributesto malicious fork commits.composer require/updatethen pulls asrc/helpers.phpbackdoor, autoloaded on every PHP request, that exfiltrates cloud and CI/CD secrets toflipboxstudio.info.PackagistAffected packages4 packages · 0 versions
- Packagistlaravel-lang/actions
- Packagistlaravel-lang/attributes
- Packagistlaravel-lang/http-statuses
- Packagistlaravel-lang/lang
packagist-2026-05-22-laravel-lang-tag-hijackSource advisory - Critical22 May 202634 packages tracked
TrapDoor / AuditorTrap crypto-stealer campaign across npm, PyPI and crates.io
Starting 2026-05-22 the TrapDoor / AuditorTrap campaign pushed 34+ malicious packages (384+ versions) across npm, PyPI and crates.io posing as crypto/DeFi/AI dev tools and fake "security guild" branding. Payloads steal SSH keys, cloud credentials and Solana/Sui/Aptos wallets, and hide zero-width-Unicode prompt injection in
CLAUDE.md/.cursorrulesto trick Claude Code and Cursor into running the stealer.crates.ionpmPyPIAffected packages34 packages · 404 versions
- npmasync-pipeline-builder1.0.01.0.11.0.31.0.41.0.51.0.61.0.81.0.91.0.101.0.111.0.121.0.131.0.141.1.01.2.01.3.01.4.01.5.01.5.1
- npmbuild-scripts-utils1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.81.0.91.0.101.0.111.0.121.0.131.0.141.1.01.2.01.3.01.4.01.5.01.5.1
- npmchain-key-validator0.2.10.2.20.2.30.2.41.2.01.2.11.2.21.2.31.3.01.3.11.3.21.3.31.3.41.3.51.3.61.3.71.3.81.3.94.0.0
- npmcrypto-credential-scanner2.0.02.0.12.0.22.0.33.0.03.0.13.0.23.0.33.1.03.1.13.1.23.1.33.1.43.1.53.1.63.1.73.1.83.1.94.0.0
- PyPIcryptowallet-safety
- PyPIdata-pipeline-check0.1.1
- npmdefi-env-auditor0.3.00.3.10.3.20.3.31.3.01.3.11.3.21.3.31.4.01.4.11.4.21.4.31.4.41.4.51.4.61.4.71.4.81.4.94.0.0
- PyPIdefi-risk-scanner0.1.0
- npmdefi-threat-scanner2.1.02.1.12.1.22.1.33.1.03.1.13.1.23.1.33.2.03.2.13.2.23.2.33.2.43.2.53.2.63.2.73.2.84.0.0
- npmdeployment-key-auditor0.7.10.7.20.7.30.7.41.7.01.7.11.7.21.7.31.8.01.8.11.8.21.8.31.8.41.8.51.8.61.8.71.8.81.8.94.0.0
- npmdev-env-bootstrapper1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.111.0.121.0.131.0.141.1.01.2.01.3.01.4.01.5.01.5.2
- PyPIenv-loader-cli0.1.1
- PyPIeth-security-auditor0.1.0
- npmeth-wallet-sentinel1.0.71.0.81.0.91.0.102.0.02.0.12.0.22.0.32.1.02.1.12.1.22.1.32.1.42.1.52.1.62.1.72.1.82.1.94.0.0
- PyPIgit-config-sync0.1.1
- npmllm-context-compressor1.0.01.0.11.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.111.0.121.0.131.0.141.1.01.2.01.3.01.4.01.5.01.5.1
- npmmnemonic-safety-check0.5.00.5.10.5.20.5.31.5.01.5.11.5.21.5.31.6.01.6.11.6.21.6.31.6.41.6.51.6.61.6.71.6.81.6.94.0.0
- npmmodel-switch-router1.0.01.0.11.0.31.0.41.0.51.0.61.0.81.0.91.0.101.0.111.0.121.0.131.0.141.1.01.2.01.3.01.4.01.5.01.5.1
- crates.iomove-analyzer-build
- crates.iomove-compiler-tools
- crates.iomove-project-builder
- npmnode-setup-helpers1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.81.0.91.0.101.0.111.0.121.0.131.0.141.1.01.2.01.3.01.4.01.5.01.5.1
- npmproject-init-tools1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.81.0.91.0.101.0.111.0.121.0.131.0.141.1.01.2.01.3.01.4.01.5.01.5.1
- npmprompt-engineering-toolkit1.0.01.0.11.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.111.0.121.0.131.0.141.1.01.2.01.3.01.4.01.5.01.5.1
- PyPIsolidity-build-guard
- npmsolidity-deploy-guard0.4.20.4.30.4.40.4.51.4.01.4.11.4.21.4.31.5.01.5.11.5.21.5.31.5.41.5.51.5.61.5.71.5.84.0.0
- crates.iosui-framework-helpers
- crates.iosui-move-build-helper
- crates.iosui-sdk-build-utils
- npmtoken-usage-tracker1.0.01.0.11.0.31.0.41.0.51.0.61.0.81.0.91.0.101.0.111.0.121.0.131.0.141.1.01.2.01.3.01.4.01.5.01.5.1
- npmwallet-backup-verifier1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.91.0.101.0.114.0.0
- npmwallet-security-checker1.0.11.0.21.0.31.0.42.0.02.0.12.0.22.0.32.1.02.1.12.1.22.1.32.1.42.1.52.1.62.1.72.1.84.0.0
- npmweb3-secrets-detector1.2.31.2.41.2.51.2.61.2.72.2.02.2.12.2.22.2.32.3.02.3.12.3.22.3.32.3.42.3.52.3.62.3.72.3.82.3.94.0.0
- npmworkspace-config-loader1.0.01.0.11.0.21.0.31.0.41.0.51.0.61.0.81.0.91.0.101.0.111.0.121.0.131.0.141.1.01.2.01.3.01.4.01.5.01.5.1
multi-2026-05-22-trapdoor-crypto-stealerSource advisory - npmasync-pipeline-builder
- High22 May 20268 packages tracked
Packagist cross-ecosystem postinstall attack - 8 Composer packages drop Linux `gvfsd-network` binary
Socket disclosed on 2026-05-23 a coordinated campaign that planted a malicious
postinstallhook in thepackage.json(NOTcomposer.json) of eight Packagist Composer packages - includingdevdojo/wave,devdojo/genesis, andkatanaui/katana. The hook curls a Linux binarygvfsd-networkfromgithub.com/parikhpreyash4/systemd-network-helper-aa5c751f, writes it to/tmp/.sshd, and runs it backgrounded. Socket flagged the same payload in 700+ public GitHub repos.PackagistAffected packages8 packages · 0 versions
- Packagistbaskarcm/tzi-chat-ui
- Packagistcrosiersource/crosierlib-base
- Packagistdevdojo/genesis
- Packagistdevdojo/wave
- Packagistelitedevsquad/sidecar-laravel
- Packagistkatanaui/katana
- Packagistmoritz-sauer-13/silverstripe-cms-theme
- Packagistr2luna/brain
packagist-2026-05-22-cross-ecosystem-postinstall-binarySource advisory - High21 May 20261 package tracked
@common-stack/generate-plugin hijacked - PolinRider-linked RAT in two alpha releases
Sonatype disclosed on 2026-05-21 that two alpha releases of
@common-stack/generate-plugin(9.0.2-alpha.21,9.0.2-alpha.22, published ~2026-05-20–21) ship an install-time stager that pulls a second-stage RAT. Tradecraft overlaps the DPRK-linked PolinRider / Contagious Interview cluster. Package draws ~1,100 weekly downloads as a Node.js plugin scaffolding helper, so any developer machine that ran it during local install should be treated as compromised.npmAffected packages1 package · 2 versions
- npm@common-stack/generate-plugin9.0.2-alpha.219.0.2-alpha.22
npm-2026-05-21-common-stack-generate-plugin-polinriderSource advisory - npm@common-stack/generate-plugin
- Critical19 May 2026298 packages tracked
@antv maintainer takeover (atool) - Mini Shai-Hulud burst across ~300 packages
On 2026-05-19 the compromised npm publisher
atool(Alibaba / AntV co-maintainer) pushed an automated burst of 639 malicious versions across 323 unique packages - the entire@antvvisualization suite plus widely-used unscoped libraries includingecharts-for-react,size-sensor, andtimeago.js(>15M combined monthly downloads). Each release adds apreinstall: bun run index.jshook running the Mini Shai-Hulud credential-stealer. Attributed to TeamPCP.npmAffected packages298 packages · 599 versions
- npm@antv/a80.1.10.2.1
- npm@antv/adjust0.3.50.4.5
- npm@antv/algorithm0.2.260.3.26
- npm@antv/async-hook2.3.92.4.9
- npm@antv/attr0.4.50.5.5
- npm@antv/ava3.5.13.6.1
- npm@antv/ava-react3.4.23.5.2
- npm@antv/awards0.1.90.2.9
- npm@antv/calendar-heatmap1.2.21.3.2
- npm@antv/chart-linter1.2.61.3.6
- npm@antv/chart-node-g60.1.40.2.4
- npm@antv/chart-visualization-skills0.2.30.3.3
- npm@antv/ckb2.1.42.2.4
- npm@antv/color-schema0.3.30.4.3
- npm@antv/color-util2.1.62.2.6
- npm@antv/component2.2.112.3.11
- npm@antv/coord0.5.70.6.7
- npm@antv/d3-color1.1.01.2.0
- npm@antv/d3-interpolate1.1.31.2.3
- npm@antv/data-samples1.1.11.2.1
- npm@antv/data-set0.12.80.13.8
- npm@antv/data-wizard2.1.42.2.4
- npm@antv/dipper-component0.1.40.2.4
- npm@antv/dipper-hooks0.3.10.4.1
- npm@antv/dipper-map1.1.101.2.10
- npm@antv/dom-util2.1.42.2.4
- npm@antv/dumi-theme-antv0.9.40.10.4
- npm@antv/dw-analyzer1.2.51.3.5
- npm@antv/dw-random1.2.71.3.7
- npm@antv/dw-transform1.2.71.3.7
- npm@antv/dw-util1.2.41.3.4
- npm@antv/event-emitter0.2.30.3.3
- npm@antv/expr1.1.21.2.2
- npm@antv/f-charts0.1.00.2.0
- npm@antv/f-engine1.11.01.12.0
- npm@antv/f-lottie1.11.01.12.0
- npm@antv/f-my1.11.01.12.0
- npm@antv/f-react1.11.01.12.0
- npm@antv/f-test-utils1.1.91.2.9
- npm@antv/f-vue1.11.01.12.0
- npm@antv/f-wx1.11.01.12.0
- npm@antv/f25.15.05.16.0
- npm@antv/f2-algorithm5.8.05.9.0
- npm@antv/f2-canvas1.1.51.2.5
- npm@antv/f2-context0.1.10.2.1
- npm@antv/f2-graphic0.1.160.2.16
- npm@antv/f2-my4.1.524.2.52
- npm@antv/f2-react5.15.05.16.0
- npm@antv/f2-site4.1.424.2.42
- npm@antv/f2-vue4.1.334.2.33
- npm@antv/f2-wordcloud5.15.05.16.0
- npm@antv/f2-wx4.1.514.2.51
- npm@antv/f60.1.190.2.19
- npm@antv/f6-alipay0.1.70.2.7
- npm@antv/f6-core0.1.20.2.2
- npm@antv/f6-element0.1.10.2.1
- npm@antv/f6-hammerjs0.1.20.2.2
- npm@antv/f6-plugin1.1.61.2.6
- npm@antv/f6-ui1.1.31.2.3
- npm@antv/f6-wx0.1.70.2.7
- npm@antv/g6.4.16.5.1
- npm@antv/g-base0.6.160.7.16
- npm@antv/g-camera-api2.1.452.2.45
- npm@antv/g-canvas2.3.02.4.0
- npm@antv/g-canvaskit1.2.11.3.1
- npm@antv/g-compat1.1.111.2.11
- npm@antv/g-components2.1.422.2.42
- npm@antv/g-css-layout-api1.1.381.2.38
- npm@antv/g-css-typed-om-api1.1.381.2.38
- npm@antv/g-device-api1.7.131.8.13
- npm@antv/g-dom-mutation-observer-api2.1.422.2.42
- npm@antv/g-gesture3.1.423.2.42
- npm@antv/g-image-exporter1.1.421.2.42
- npm@antv/g-layout-blocklike1.8.491.9.49
- npm@antv/g-lite2.8.02.9.0
- npm@antv/g-lottie-player1.2.11.3.1
- npm@antv/g-math3.2.03.3.0
- npm@antv/g-mobile1.2.51.3.5
- npm@antv/g-mobile-canvas1.2.11.3.1
- npm@antv/g-mobile-canvas-element1.1.421.2.42
- npm@antv/g-mobile-svg1.2.11.3.1
- npm@antv/g-mobile-webgl1.2.11.3.1
- npm@antv/g-pattern2.1.422.2.42
- npm@antv/g-perf1.1.01.2.0
- npm@antv/g-plugin-3d2.2.12.3.1
- npm@antv/g-plugin-a11y1.5.11.6.1
- npm@antv/g-plugin-annotation1.3.01.4.0
- npm@antv/g-plugin-box2d2.2.12.3.1
- npm@antv/g-plugin-canvas-path-generator2.2.262.3.26
- npm@antv/g-plugin-canvas-picker2.4.12.5.1
- npm@antv/g-plugin-canvas-renderer2.6.12.7.1
- npm@antv/g-plugin-canvaskit-renderer2.4.12.5.1
- npm@antv/g-plugin-control2.2.12.3.1
- npm@antv/g-plugin-css-select2.2.12.3.1
- npm@antv/g-plugin-device-renderer2.7.12.8.1
- npm@antv/g-plugin-dom-interaction2.2.312.3.31
- npm@antv/g-plugin-dragndrop2.2.12.3.1
- npm@antv/g-plugin-gesture2.2.12.3.1
- npm@antv/g-plugin-gpgpu1.10.201.11.20
- npm@antv/g-plugin-html-renderer2.4.12.5.1
- npm@antv/g-plugin-image-loader2.4.12.5.1
- npm@antv/g-plugin-matterjs2.2.12.3.1
- npm@antv/g-plugin-mobile-interaction1.1.421.2.42
- npm@antv/g-plugin-physx2.2.12.3.1
- npm@antv/g-plugin-rough-canvas-renderer2.2.12.3.1
- npm@antv/g-plugin-rough-svg-renderer2.2.12.3.1
- npm@antv/g-plugin-svg-picker2.1.462.2.46
- npm@antv/g-plugin-svg-renderer2.5.12.6.1
- npm@antv/g-plugin-webgl-device1.10.171.11.17
- npm@antv/g-plugin-webgl-renderer1.1.261.2.26
- npm@antv/g-plugin-webgpu-device1.10.171.11.17
- npm@antv/g-plugin-yoga2.4.12.5.1
- npm@antv/g-plugin-zdog-canvas-renderer2.2.12.3.1
- npm@antv/g-plugin-zdog-svg-renderer2.2.12.3.1
- npm@antv/g-shader-components2.1.02.2.0
- npm@antv/g-svg2.2.12.3.1
- npm@antv/g-web-animations-api2.2.322.3.32
- npm@antv/g-web-components2.2.12.3.1
- npm@antv/g-webgl2.2.12.3.1
- npm@antv/g-webgl-compute0.1.10.2.1
- npm@antv/g-webgpu2.2.12.3.1
- npm@antv/g-webgpu-compiler0.8.20.9.2
- npm@antv/g-webgpu-core0.8.20.9.2
- npm@antv/g-webgpu-engine0.8.20.9.2
- npm@antv/g-webgpu-raytracer0.6.10.7.1
- npm@antv/g-webgpu-unitchart0.6.10.7.1
- npm@antv/g25.5.85.6.8
- npm@antv/g2-brush0.1.20.2.2
- npm@antv/g2-extension-3d0.3.00.4.0
- npm@antv/g2-extension-ava0.3.00.4.0
- npm@antv/g2-extension-plot0.3.20.4.2
- npm@antv/g2-plugin-slider2.2.12.3.1
- npm@antv/g2-ssr0.3.00.4.0
- npm@antv/g2plot2.5.352.6.35
- npm@antv/g2plot-schemas1.3.21.4.2
- npm@antv/g65.2.15.3.1
- npm@antv/g6-alipay0.1.10.2.1
- npm@antv/g6-cli0.1.40.2.4
- npm@antv/g6-core0.9.240.10.24
- npm@antv/g6-editor1.3.01.4.0
- npm@antv/g6-element0.9.250.10.25
- npm@antv/g6-extension-3d0.2.230.3.23
- npm@antv/g6-extension-react0.3.70.4.7
- npm@antv/g6-mobile0.2.20.3.2
- npm@antv/g6-pc0.9.250.10.25
- npm@antv/g6-plugin0.9.250.10.25
- npm@antv/g6-plugin-map-view0.1.40.2.4
- npm@antv/g6-plugins1.1.91.2.9
- npm@antv/g6-react-node1.5.81.6.8
- npm@antv/g6-ssr0.2.10.3.1
- npm@antv/g6-wx0.1.10.2.1
- npm@antv/gatsby-theme0.2.00.3.0
- npm@antv/geo-coord1.1.81.2.8
- npm@antv/gi-assets-advance2.6.222.7.22
- npm@antv/gi-assets-algorithm2.4.192.5.19
- npm@antv/gi-assets-basic2.5.402.6.40
- npm@antv/gi-assets-galaxybase1.3.151.4.15
- npm@antv/gi-assets-graphscope2.2.152.3.15
- npm@antv/gi-assets-hugegraph1.2.151.3.15
- npm@antv/gi-assets-janusgraph1.2.151.3.15
- npm@antv/gi-assets-neo4j2.2.152.3.15
- npm@antv/gi-assets-scene2.3.212.4.21
- npm@antv/gi-assets-tugraph2.2.152.3.15
- npm@antv/gi-assets-tugraph-analytics0.3.150.4.15
- npm@antv/gi-assets-xlab0.2.300.3.30
- npm@antv/gi-cli1.3.111.4.11
- npm@antv/gi-common-components1.4.161.5.16
- npm@antv/gi-mock-data1.1.51.2.5
- npm@antv/gi-public-data1.1.11.2.1
- npm@antv/gi-sdk3.1.03.2.0
- npm@antv/gi-sdk-app1.3.101.4.10
- npm@antv/gi-theme-antd0.7.110.8.11
- npm@antv/github-config-cli0.2.00.3.0
- npm@antv/gl-matrix2.8.12.9.1
- npm@antv/gpt-vis1.1.01.2.0
- npm@antv/gpt-vis-ssr0.4.70.5.7
- npm@antv/graphin3.1.53.2.5
- npm@antv/graphin-components2.5.12.6.1
- npm@antv/graphin-graphscope1.1.51.2.5
- npm@antv/graphin-icons1.1.01.2.0
- npm@antv/graphlib2.1.42.2.4
- npm@antv/hierarchy0.8.10.9.1
- npm@antv/infographic0.3.190.4.19
- npm@antv/interaction0.2.50.3.5
- npm@antv/istanbul0.1.00.2.0
- npm@antv/knowledge1.2.41.3.4
- npm@antv/l72.26.102.27.10
- npm@antv/l7-component2.26.102.27.10
- npm@antv/l7-composite-layers0.18.10.19.1
- npm@antv/l7-core2.26.102.27.10
- npm@antv/l7-district2.4.122.5.12
- npm@antv/l7-draw3.2.53.3.5
- npm@antv/l7-editor1.2.131.3.13
- npm@antv/l7-extension-g-layer1.1.01.2.0
- npm@antv/l7-layers2.26.102.27.10
- npm@antv/l7-leaflet1.1.21.2.2
- npm@antv/l7-map2.26.102.27.10
- npm@antv/l7-mapkit0.6.00.7.0
- npm@antv/l7-maps2.26.102.27.10
- npm@antv/l7-mini2.21.82.22.8
- npm@antv/l7-pass1.1.01.2.0
- npm@antv/l7-react2.5.32.6.3
- npm@antv/l7-renderer2.26.102.27.10
- npm@antv/l7-scene2.26.102.27.10
- npm@antv/l7-source2.26.102.27.10
- npm@antv/l7-three2.26.102.27.10
- npm@antv/l7-utils2.26.102.27.10
- npm@antv/l7plot0.6.110.7.11
- npm@antv/l7plot-component0.1.110.2.11
- npm@antv/larkmap1.6.11.7.1
- npm@antv/layout-gpu1.2.71.3.7
- npm@antv/layout-wasm1.5.21.6.2
- npm@antv/li-aiearth-assets0.5.70.6.7
- npm@antv/li-analysis-assets1.10.11.11.1
- npm@antv/li-core-assets1.4.71.5.7
- npm@antv/li-editor1.7.11.8.1
- npm@antv/li-p21.9.21.10.2
- npm@antv/li-sam-assets0.2.40.3.4
- npm@antv/li-sdk1.6.11.7.1
- npm@antv/lite-insight2.2.12.3.1
- npm@antv/matrix-util3.1.43.2.4
- npm@antv/mcp-server-antv0.2.80.3.8
- npm@antv/mcp-server-chart0.10.100.11.10
- npm@antv/my-f22.2.72.3.7
- npm@antv/my-f2-pc0.2.10.3.1
- npm@antv/narrative-text-editor0.3.200.4.20
- npm@antv/narrative-text-schema0.4.70.5.7
- npm@antv/narrative-text-vis0.4.160.5.16
- npm@antv/path-util3.1.13.2.1
- npm@antv/react-g2.2.12.3.1
- npm@antv/s22.8.12.9.1
- npm@antv/s2-react2.4.12.5.1
- npm@antv/s2-react-components2.2.22.3.2
- npm@antv/s2-ssr0.2.10.3.1
- npm@antv/s2-vue2.3.02.4.0
- npm@antv/sam0.3.00.4.0
- npm@antv/scale0.6.20.7.2
- npm@antv/semantic-release-pnpm1.1.41.2.4
- npm@antv/smart-color0.3.10.4.1
- npm@antv/stat0.1.20.2.2
- npm@antv/t80.4.00.5.0
- npm@antv/thumbnails2.1.02.2.0
- npm@antv/thumbnails-component2.1.02.2.0
- npm@antv/torch1.1.61.2.6
- npm@antv/translator1.1.11.2.1
- npm@antv/util3.4.113.5.11
- npm@antv/vendor1.1.111.2.11
- npm@antv/vis-predict-engine0.2.10.3.1
- npm@antv/webgpu-graph1.1.01.2.0
- npm@antv/word-scale-chart0.4.40.5.4
- npm@antv/wx-f22.2.12.3.1
- npm@antv/x63.2.73.3.7
- npm@antv/x6-angular-shape3.1.13.2.1
- npm@antv/x6-components0.11.70.12.7
- npm@antv/x6-react0.2.260.3.26
- npm@antv/x6-react-shape3.1.13.2.1
- npm@antv/x6-vector1.5.21.6.2
- npm@antv/x6-vue-shape3.1.23.2.2
- npm@antv/x6-vue3-shape1.1.01.2.0
- npm@antv/xflow2.2.132.3.13
- npm@antv/xflow-diff1.1.01.2.0
- npm@lint-md/cli2.1.02.2.0
- npm@lint-md/core2.1.02.2.0
- npm@lint-md/parser0.1.140.2.14
- npmai-figure0.5.00.6.0
- npmamapcn0.2.20.3.2
- npmast-plugin0.1.70.2.7
- npmbabel-plugin-version0.3.30.4.3
- npmboring-avatars-vanilla1.1.21.2.2
- npmbyte-parser1.1.01.2.0
- npmcanvas-nest.js2.1.42.2.4
- npmecharts-for-react3.0.73.1.73.2.7
- npmfilesize.js2.1.02.2.0
- npmfixed-round1.1.21.2.2
- npmgantt-for-react0.3.00.4.0
- npmjest-canvas-mock2.5.32.6.32.7.3
- npmjest-date-mock1.0.111.1.111.2.11
- npmjest-electron0.2.120.3.12
- npmjest-expect0.1.10.2.1
- npmjest-less-loader0.3.00.4.0
- npmjest-random-mock1.1.01.2.0
- npmjest-url-loader0.2.00.3.0
- npmlimit-size0.2.40.3.4
- npmlint-md0.3.00.4.0
- npmlint-md-cli0.2.20.3.2
- npmmcp-echarts0.8.10.9.1
- npmmcp-mermaid0.5.10.6.1
- npmmiz1.1.11.2.1
- npmonfire.js2.1.12.2.1
- npmreact-adsense0.2.00.3.0
- npmrelationship.js1.3.91.4.9
- npmribbon.js1.1.2
- npmsize-sensor1.0.41.1.41.2.4
- npmslice.js1.2.11.3.1
- npmtimeago-react3.1.73.2.7
- npmtimeago.js4.1.24.2.2
- npmword-width1.1.11.2.1
- npmxmorse1.1.01.2.0
npm-2026-05-19-antv-mini-shai-huludSource advisory - npm@antv/a8
- Critical19 May 20261 package tracked
Microsoft `durabletask` PyPI compromised - TeamPCP Mini Shai-Hulud stage-2 dropper
Three malicious versions of
durabletask- Microsoft's Python SDK for Azure Durable Functions (~417K monthly downloads) - were uploaded directly to PyPI inside a 35-minute window on 2026-05-19. None correspond to any git tag or CI run; the attacker bypassed Microsoft's pipeline with a stolen PyPI API token. Stage-2 is the full Mini Shai-Hulud credential-stealer with dedicated cloud-secret collectors. Attributed to TeamPCP. Last clean release:1.4.0.PyPIAffected packages1 package · 3 versions
- PyPIdurabletask1.4.11.4.21.4.3
pypi-2026-05-19-durabletask-teampcpSource advisory - PyPIdurabletask
- Critical19 May 20262 packages tracked
actions-cool/issues-helper + maintain-one-comment - every tag retargeted to TeamPCP imposter commit
On 2026-05-19 an attacker with push access to the
actions-coolGitHub org force-moved every tag inactions-cool/issues-helper(53 tags, including the floatingv1/v2) andactions-cool/maintain-one-comment(15 tags) to a single imposter commit. Any workflow pinned to a tag - not a full commit SHA - pulled the imposterdist/index.js, which dumpsRunner.Workermemory to exfiltrate GitHub Actions secrets. Shares C2 (t.m-kosche.com) with the same-day @antv anddurabletaskwaves; attributed to TeamPCP.GitHub ActionsAffected packages2 packages · 0 versions
- GitHub Actionsactions-cool/issues-helper
- GitHub Actionsactions-cool/maintain-one-comment
github-actions-2026-05-19-actions-cool-tag-hijackSource advisory - High19 May 20261 package tracked
shopsprint/decimal Go typosquat ships a DNS-TXT command-and-control backdoor
Socket disclosed a long-running Go typosquat of
github.com/shopspring/decimalpublished asgithub.com/shopsprint/decimal(single-letter swap,tforg). The typosquat was registered 2017-11-08 and was weaponised on 2023-08-19 inv1.3.3, which adds a maliciousinit()that polls a free-dynamic-DNS subdomain for TXT-record commands every five minutes and executes the response viaos/exec. Dwell time before disclosure: ~33 months.GoAffected packages1 package · 1 version
- Gogithub.com/shopsprint/decimalv1.3.3
go-2026-05-19-shopsprint-decimal-dns-backdoorSource advisory - Gogithub.com/shopsprint/decimal
- Critical18 May 20261 package tracked
Nx Console (nrwl.angular-console) 18.95.0 hijacked via TanStack-stolen GitHub creds
A malicious
Nx Console v18.95.0(publishernrwl, ~2.2M installs across VS Code, Cursor, and JetBrains) shipped to both the VS Code Marketplace and Open VSX on 2026-05-18, live for ~18–36 minutes. Every workspace open fetched a 498KB Mini Shai-Hulud stage-2 dropper from an orphan commit innrwl/nx. Nx telemetry estimates ~6,000 users received the build. Root cause: the May 11 TanStack compromise leaked one Nx Console maintainer's GitHub CLI credentials. Tracked asGHSA-c9j4-9m59-847w/CVE-2026-48027.Open VSXAffected packages1 package · 1 version
- Open VSXnrwl.angular-console18.95.0
openvsx-2026-05-18-nx-console-nrwl-angular-consoleSource advisory - Open VSXnrwl.angular-console
- Critical18 May 202610 packages tracked
Megalodon: automated CI/CD workflow injection backdoors 5,561 GitHub repos, propagates to @tiledesk/tiledesk-server on npm
On 2026-05-18 an automated campaign nicknamed
Megalodonpushed 5,718 commits to 5,561 public GitHub repos in six hours, injecting GitHub Actions workflows that exfiltrate CI secrets to216.126.225.129:8443. The legitimate Tiledesk maintainer then released@tiledesk/tiledesk-server2.18.6–2.18.12 from the poisoned source - propagating the backdoor to every downstream npm install.GitHub ActionsnpmAffected packages10 packages · 7 versions
- npm@tiledesk/tiledesk-server2.18.62.18.72.18.82.18.92.18.102.18.112.18.12
- GitHub Actionstiledesk/tiledesk-ai
- GitHub Actionstiledesk/tiledesk-campaign-dashboard
- GitHub Actionstiledesk/tiledesk-community-app
- GitHub Actionstiledesk/tiledesk-dashboard
- GitHub Actionstiledesk/tiledesk-docker-proxy
- GitHub Actionstiledesk/tiledesk-helpcenter-template
- GitHub Actionstiledesk/tiledesk-llm
- GitHub Actionstiledesk/tiledesk-server
- GitHub Actionstiledesk/tiledesk-telegram-connector
multi-2026-05-18-megalodon-tiledeskSource advisory - npm@tiledesk/tiledesk-server
- High16 May 20264 packages tracked
Leaked Shai-Hulud + Phantom Bot copycats from npm user deadcode09284814
Three days after TeamPCP open-sourced the Shai-Hulud worm code (2026-05-13), npm publisher
deadcode09284814pushed four malicious packages on 2026-05-16:@deadcode09284814/axios-util,axois-utils,chalk-tempalte, andcolor-style-utils.chalk-tempalteis the first documented in-the-wild Shai-Hulud clone - a near-verbatim copy of the leaked source with a swapped C2. Tradecraft is well below TeamPCP standard; this is the first copycat wave riding the leak.npmAffected packages4 packages · 21 versions
- npm@deadcode09284814/axios-util1.0.01.0.1
- npmaxois-utils1.0.41.0.51.0.61.0.71.0.81.0.9
- npmchalk-tempalte1.0.141.0.151.0.161.0.171.0.191.0.20
- npmcolor-style-utils1.0.31.0.41.0.51.0.61.0.71.0.81.0.9
npm-2026-05-16-shai-hulud-leak-copycats-deadcodeSource advisory - npm@deadcode09284814/axios-util
- Critical14 May 20261 package tracked
node-ipc dormant-maintainer takeover via expired email domain
On 2026-05-14 three malicious
node-ipcreleases (9.1.6,9.2.3,12.0.1) were published from a dormant maintainer accountatiertant. The attacker re-registered the expiredatlantis-software.netdomain on 2026-05-07 and used npm's password-reset flow to seize publish rights. The payload fires on everyrequire("node-ipc")(no lifecycle hook) and exfiltrates 90+ credential categories via DNS TXT queries.12.0.1was taggedlatest, so any unpinned install during the ~60-second window pulled the backdoor. ~822K weekly downloads.npmAffected packages1 package · 3 versions
- npmnode-ipc9.1.69.2.312.0.1
npm-2026-05-14-node-ipc-dormant-takeoverSource advisory - npmnode-ipc
- Critical11 May 2026177 packages tracked
TanStack + @uipath mini-Shai-Hulud compromise
On 2026-05-11 between 19:20 and 19:26 UTC, TeamPCP pushed malicious versions across
@tanstack/*,@uipath/*,@mistralai/*, and many smaller scopes by chainingpull_request_target, GitHub Actions cache poisoning, and runtime OIDC-token extraction from a runner. Same Mini Shai-Hulud credential-stealer as the April SAP campaign. Final tally: 177 packages, 403 versions, >518M cumulative downloads. OpenAI confirmed two compromised employee devices and rotated platform code-signing certificates.npmPyPIAffected packages179 packages · 413 versions
- npm@beproduct/nestjs-auth0.1.20.1.30.1.40.1.50.1.60.1.70.1.80.1.90.1.100.1.110.1.120.1.130.1.140.1.150.1.160.1.170.1.180.1.19
- npm@cap-js/db-service2.10.1
- npm@cap-js/postgres2.2.2
- npm@cap-js/sqlite2.2.2
- npm@dirigible-ai/sdk0.6.20.6.3
- npm@draftauth/client0.2.10.2.2
- npm@draftauth/core0.13.10.13.2
- npm@draftlab/auth0.24.10.24.2
- npm@draftlab/auth-router0.5.10.5.2
- npm@draftlab/db0.16.10.16.2
- npm@mesadev/rest0.28.3
- npm@mesadev/saguaro0.4.22
- npm@mesadev/sdk0.28.3
- npm@mistralai/mistralai2.2.22.2.32.2.4
- npm@mistralai/mistralai-azure1.7.11.7.21.7.3
- npm@mistralai/mistralai-gcp1.7.11.7.21.7.3
- npm@ml-toolkit-ts/preprocessing1.0.21.0.3
- npm@ml-toolkit-ts/xgboost1.0.31.0.4
- npm@opensearch-project/opensearch3.5.33.6.23.7.03.8.0
- npm@squawk/airport-data0.7.40.7.50.7.60.7.70.7.8
- npm@squawk/airports0.6.20.6.30.6.40.6.50.6.6
- npm@squawk/airspace0.8.10.8.20.8.30.8.40.8.5
- npm@squawk/airspace-data0.5.30.5.40.5.50.5.60.5.7
- npm@squawk/airway-data0.5.40.5.50.5.60.5.70.5.8
- npm@squawk/airways0.4.20.4.30.4.40.4.50.4.6
- npm@squawk/fix-data0.6.40.6.50.6.60.6.70.6.8
- npm@squawk/fixes0.3.20.3.30.3.40.3.50.3.6
- npm@squawk/flight-math0.5.40.5.50.5.60.5.70.5.8
- npm@squawk/flightplan0.5.20.5.30.5.40.5.50.5.6
- npm@squawk/geo0.4.40.4.50.4.60.4.70.4.8
- npm@squawk/icao-registry0.5.20.5.30.5.40.5.50.5.6
- npm@squawk/icao-registry-data0.8.40.8.50.8.60.8.70.8.8
- npm@squawk/mcp0.9.10.9.20.9.30.9.40.9.5
- npm@squawk/navaid-data0.6.40.6.50.6.60.6.70.6.8
- npm@squawk/navaids0.4.20.4.30.4.40.4.50.4.6
- npm@squawk/notams0.3.60.3.70.3.80.3.90.3.10
- npm@squawk/procedure-data0.7.30.7.40.7.50.7.60.7.7
- npm@squawk/procedures0.5.20.5.30.5.40.5.50.5.6
- npm@squawk/types0.8.10.8.20.8.30.8.40.8.5
- npm@squawk/units0.4.30.4.40.4.50.4.60.4.7
- npm@squawk/weather0.5.60.5.70.5.80.5.90.5.10
- npm@supersurkhet/cli0.0.20.0.30.0.40.0.50.0.60.0.7
- npm@supersurkhet/sdk0.0.20.0.30.0.40.0.50.0.60.0.7
- npm@tallyui/components1.0.11.0.21.0.3
- npm@tallyui/connector-medusa1.0.11.0.21.0.3
- npm@tallyui/connector-shopify1.0.11.0.21.0.3
- npm@tallyui/connector-vendure1.0.11.0.21.0.3
- npm@tallyui/connector-woocommerce1.0.11.0.21.0.3
- npm@tallyui/core0.2.10.2.20.2.3
- npm@tallyui/database1.0.11.0.21.0.3
- npm@tallyui/pos0.1.10.1.20.1.3
- npm@tallyui/storage-sqlite0.2.10.2.20.2.3
- npm@tallyui/theme0.2.10.2.20.2.3
- npm@tanstack/arktype-adapter1.166.121.166.15
- npm@tanstack/eslint-plugin-router1.161.91.161.12
- npm@tanstack/eslint-plugin-start0.0.40.0.7
- npm@tanstack/history1.161.91.161.12
- npm@tanstack/nitro-v2-vite-plugin1.154.121.154.15
- npm@tanstack/react-router1.169.51.169.8
- npm@tanstack/react-router-devtools1.166.161.166.19
- npm@tanstack/react-router-ssr-query1.166.151.166.18
- npm@tanstack/react-start1.167.681.167.71
- npm@tanstack/react-start-client1.166.511.166.54
- npm@tanstack/react-start-rsc0.0.470.0.50
- npm@tanstack/react-start-server1.166.551.166.58
- npm@tanstack/router-cli1.166.461.166.49
- npm@tanstack/router-core1.169.51.169.8
- npm@tanstack/router-devtools1.166.161.166.19
- npm@tanstack/router-devtools-core1.167.61.167.9
- npm@tanstack/router-generator1.166.451.166.48
- npm@tanstack/router-plugin1.167.381.167.41
- npm@tanstack/router-ssr-query-core1.168.31.168.6
- npm@tanstack/router-utils1.161.111.161.14
- npm@tanstack/router-vite-plugin1.166.531.166.56
- npm@tanstack/solid-router1.169.51.169.8
- npm@tanstack/solid-router-devtools1.166.161.166.19
- npm@tanstack/solid-router-ssr-query1.166.151.166.18
- npm@tanstack/solid-start1.167.651.167.68
- npm@tanstack/solid-start-client1.166.501.166.53
- npm@tanstack/solid-start-server1.166.541.166.57
- npm@tanstack/start-client-core1.168.51.168.8
- npm@tanstack/start-fn-stubs1.161.91.161.12
- npm@tanstack/start-plugin-core1.169.231.169.26
- npm@tanstack/start-server-core1.167.331.167.36
- npm@tanstack/start-static-server-functions1.166.441.166.47
- npm@tanstack/start-storage-context1.166.381.166.41
- npm@tanstack/valibot-adapter1.166.121.166.15
- npm@tanstack/virtual-file-routes1.161.101.161.13
- npm@tanstack/vue-router1.169.51.169.8
- npm@tanstack/vue-router-devtools1.166.161.166.19
- npm@tanstack/vue-router-ssr-query1.166.151.166.18
- npm@tanstack/vue-start1.167.611.167.64
- npm@tanstack/vue-start-client1.166.461.166.49
- npm@tanstack/vue-start-server1.166.501.166.53
- npm@tanstack/zod-adapter1.166.121.166.15
- npm@taskflow-corp/cli0.1.240.1.250.1.260.1.270.1.280.1.29
- npm@tolka/cli1.0.21.0.31.0.41.0.51.0.6
- npm@uipath/access-policy-sdk0.3.1
- npm@uipath/access-policy-tool0.3.1
- npm@uipath/admin-tool0.1.1
- npm@uipath/agent-sdk1.0.2
- npm@uipath/agent-tool1.0.1
- npm@uipath/agent.sdk0.0.18
- npm@uipath/aops-policy-tool0.3.1
- npm@uipath/ap-chat1.5.7
- npm@uipath/api-workflow-tool1.0.1
- npm@uipath/apollo-core5.9.2
- npm@uipath/apollo-react4.24.5
- npm@uipath/apollo-wind2.16.2
- npm@uipath/auth1.0.1
- npm@uipath/case-tool1.0.1
- npm@uipath/cli1.0.1
- npm@uipath/codedagent-tool1.0.1
- npm@uipath/codedagents-tool0.1.12
- npm@uipath/codedapp-tool1.0.1
- npm@uipath/common1.0.1
- npm@uipath/context-grounding-tool0.1.1
- npm@uipath/data-fabric-tool1.0.2
- npm@uipath/docsai-tool1.0.1
- npm@uipath/filesystem1.0.1
- npm@uipath/flow-tool1.0.2
- npm@uipath/functions-tool1.0.1
- npm@uipath/gov-tool0.3.1
- npm@uipath/identity-tool0.1.1
- npm@uipath/insights-sdk1.0.1
- npm@uipath/insights-tool1.0.1
- npm@uipath/integrationservice-sdk1.0.2
- npm@uipath/integrationservice-tool1.0.2
- npm@uipath/llmgw-tool1.0.1
- npm@uipath/maestro-sdk1.0.1
- npm@uipath/maestro-tool1.0.1
- npm@uipath/orchestrator-tool1.0.1
- npm@uipath/packager-tool-apiworkflow0.0.19
- npm@uipath/packager-tool-bpmn0.0.9
- npm@uipath/packager-tool-case0.0.9
- npm@uipath/packager-tool-connector0.0.19
- npm@uipath/packager-tool-flow0.0.19
- npm@uipath/packager-tool-functions0.1.1
- npm@uipath/packager-tool-webapp1.0.6
- npm@uipath/packager-tool-workflowcompiler0.0.16
- npm@uipath/packager-tool-workflowcompiler-browser0.0.34
- npm@uipath/platform-tool1.0.1
- npm@uipath/project-packager1.1.16
- npm@uipath/resource-tool1.0.1
- npm@uipath/resourcecatalog-tool0.1.1
- npm@uipath/resources-tool0.1.11
- npm@uipath/robot1.3.4
- npm@uipath/rpa-legacy-tool1.0.1
- npm@uipath/rpa-tool0.9.5
- npm@uipath/solution-packager0.0.35
- npm@uipath/solution-tool1.0.1
- npm@uipath/solutionpackager-sdk1.0.11
- npm@uipath/solutionpackager-tool-core0.0.34
- npm@uipath/tasks-tool1.0.1
- npm@uipath/telemetry0.0.7
- npm@uipath/test-manager-tool1.0.2
- npm@uipath/tool-workflowcompiler0.0.12
- npm@uipath/traces-tool1.0.1
- npm@uipath/ui-widgets-multi-file-upload1.0.1
- npm@uipath/uipath-python-bridge1.0.1
- npm@uipath/vertical-solutions-tool1.0.1
- npm@uipath/vss0.1.6
- npm@uipath/widget.sdk1.2.3
- npmagentwork-cli0.1.40.1.5
- npmcmux-agent-mcp0.1.30.1.40.1.50.1.60.1.70.1.8
- npmcross-stitch1.1.31.1.41.1.51.1.61.1.7
- npmgit-branch-selector1.3.31.3.41.3.51.3.61.3.7
- npmgit-git-git1.0.81.0.91.0.101.0.111.0.12
- npmguardrails-ai0.10.1
- PyPIguardrails-ai0.10.1
- npmintercom-client7.0.4
- npmmbt1.2.48
- npmmistralai2.4.6
- PyPImistralai2.4.6
- npmml-toolkit-ts1.0.41.0.5
- npmnextmove-mcp0.1.30.1.40.1.50.1.60.1.7
- npmsafe-action0.8.30.8.4
- npmts-dna3.0.13.0.23.0.33.0.43.0.5
- npmwot-api0.8.10.8.20.8.30.8.4
npm-2026-05-shai-hulud-tanstackSource advisory - npm@beproduct/nestjs-auth
- Medium11 May 2026Feed-only · no version-specific detection
RubyGems account-creation flood + GemStuffer data dead-drops force signup suspension
From 2026-05-11–12 an actor abused a RubyGems account-creation flaw to spin up thousands of bot accounts and upload tens of thousands of gems - 500+ confirmed malicious and yanked. Most were empty placeholders or GemStuffer data dead-drops that scraped U.K. council ModernGov portals and re-published the data as
.gemarchives. RubyGems paused new sign-ups; resolved 2026-05-16.rubygems-2026-05-11-gemstuffer-floodSource advisory - High8 May 20263 packages tracked
OceanLotus-attributed ZiChatBot PyPI droppers: uuid32-utils, colorinal, termncolor with Zulip-API C2
Kaspersky GReAT (2026-05-08) re-attributed three PyPI wheels uploaded by an attacker between 2025-07-16 and 2025-07-22 -
uuid32-utils,colorinal, andtermncolor- to the Vietnam-aligned OceanLotus (APT32) group. The droppers fetch a Windows DLL or Linux.so, persist via Run-key or crontab, and loadZiChatBot, a Python backdoor that uses public Zulip REST APIs as its C2 channel to blend with normal developer traffic.PyPIAffected packages3 packages · 7 versions
- PyPIcolorinal1.0.0
- PyPItermncolor1.0.0
- PyPIuuid32-utils1.0.01.0.11.0.21.0.31.0.4
pypi-2026-05-08-oceanlotus-zichatbot-zulip-c2Source advisory - PyPIcolorinal
- High5 May 20261 package tracked
Sicoob.Sdk NuGet impersonator exfiltrates Brazilian banking PFX certificates and passwords via Sentry telemetry abuse
Sicoob.Sdk2.0.0–2.0.4 (published to NuGet between 2026-05-05 and 2026-05-06 by an account also namedsicoob) posed as the official C# SDK for Brazilian credit cooperative Sicoob. When a developer constructedSicoobClientwith a client ID, PFX path and PFX password, the embeddedSicoob.Sdk.dllbase64-encoded the PFX file and POSTed it together with the client ID and plaintext PFX password to an attacker-controlled Sentry endpoint. NuGet blocked the package after Socket disclosure on 2026-05-29.NuGetAffected packages1 package · 5 versions
- NuGetSicoob.Sdk2.0.02.0.12.0.22.0.32.0.4
nuget-2026-05-05-sicoob-sdk-banking-impersonatorSource advisory - NuGetSicoob.Sdk
- High1 May 202616 packages tracked
BufferZoneCorp sleeper attack on RubyGems + Go modules
Socket disclosed a coordinated sleeper-package campaign attributed to the GitHub org
BufferZoneCorp(and RubyGems userknot-theory). Initially-clean Ruby gems and Go modules were updated to malicious versions. The Ruby side harvests env vars, SSH keys, AWS secrets, .npmrc, .netrc, GitHub CLI config, and RubyGems credentials; the Go side tampers with GitHub Actions workflows, injects fake executables, and adds SSH persistence via authorized_keys. First confirmed 2026 RubyGems + Go module supply-chain campaign.GoRubyGemsAffected packages16 packages · 0 versions
- Gogithub.com/BufferZoneCorp/config-loader
- Gogithub.com/BufferZoneCorp/go-envconfig
- Gogithub.com/BufferZoneCorp/go-metrics-sdk
- Gogithub.com/BufferZoneCorp/go-retryablehttp
- Gogithub.com/BufferZoneCorp/go-stdlib-ext
- Gogithub.com/BufferZoneCorp/go-weather-sdk
- Gogithub.com/BufferZoneCorp/grpc-client
- Gogithub.com/BufferZoneCorp/log-core
- Gogithub.com/BufferZoneCorp/net-helper
- RubyGemsknot-activesupport-logger
- RubyGemsknot-date-utils-rb
- RubyGemsknot-devise-jwt-helper
- RubyGemsknot-rack-session-store
- RubyGemsknot-rails-assets-pipeline
- RubyGemsknot-rspec-formatter-json
- RubyGemsknot-simple-formatter
multi-2026-05-01-bufferzonecorp-rubygems-goSource advisory - Critical30 Apr 20263 packages tracked
PyTorch Lightning + intercom-client + intercom-php coordinated push
Mini Shai-Hulud wave 2: coordinated April 30 release of
lightning2.6.2/2.6.3 (PyPI),intercom-client7.0.4/7.0.5 (npm), andintercom/intercom-php5.0.2 (Packagist) carrying the same Bun-based credential stealer used in the SAP/@cap-js wave. ~11.7MBrouter_runtime.jsfires preinstall on npm; a.pthfile fires at every Python import on PyPI. Worm propagation via stolen GitHub PATs labelled "OhNoWhatsGoingOnWithGitHub:".npmPackagistPyPIAffected packages3 packages · 5 versions
- npmintercom-client7.0.47.0.5
- Packagistintercom/intercom-php5.0.2
- PyPIlightning2.6.22.6.3
multi-2026-04-30-mini-shai-hulud-wave2Source advisory - npmintercom-client
- High29 Apr 202610 packages tracked
DPRK "PromptMink" campaign uses AI agents to insert @validate-sdk/v2 dependency
ReversingLabs traced a DPRK Famous Chollima / UNC1069 campaign that began with
@hash-validator/v2in Sept 2025 and evolved through Feb 28, 2026 to insert@validate-sdk/v2as the malicious dependency of benign-looking "bait" SDKs aimed at AI coding agents. One AI-authored commit pulled@solana-launchpad/sdkinto a crypto trading repo. Phase 4 in March 2026 used Rust NAPI modules and 85MB Node SEA bundles to exfiltrate full source trees. 300+ malicious package versions across 60+ unique packages observed.npmPyPIAffected packages10 packages · 36 versions
- npm@hash-validator/v2
- npm@meme-sdk/trade1.0.01.0.1
- npm@pumpfun-ipfs/sdk
- npm@solana-ipfs/sdk
- npm@solana-launchpad/sdk
- npm@solmasterv3/solana-metadata-sdk
- npm@validate-ethereum-address/core1.0.31.0.41.0.51.0.6
- npm@validate-sdk/v21.22.111.22.121.22.131.22.141.22.151.22.161.22.171.22.181.22.191.22.201.22.211.22.221.22.231.22.241.22.251.22.261.22.271.22.281.22.291.22.301.22.31
- npm@validator-sdk/pubkey1.0.01.0.21.0.31.0.41.0.51.0.61.0.71.0.8
- PyPIscraper-npm1.0.4
multi-2026-04-29-promptmink-validate-sdkSource advisory - Critical29 Apr 20264 packages tracked
SAP / @cap-js mini-Shai-Hulud campaign
Mini-Shai-Hulud-style attack against SAP-related npm packages on 2026-04-29 09:55–12:14 UTC. Preinstall
setup.mjsdownloads the Bun runtime, runs an obfuscatedexecution.jsthat exfils GitHub/npm tokens, AWS/Azure/GCP secrets, Kubernetes tokens, and browser passwords via the GitHub GraphQL API. Includes a Russian-locale guardrail and persistence via .claude/ and .vscode/ poisoning.npmAffected packages4 packages · 4 versions
- npm@cap-js/db-service2.10.1
- npm@cap-js/postgres2.2.2
- npm@cap-js/sqlite2.2.2
- npmmbt1.2.48
npm-2026-04-sap-cap-jsSource advisory - npm@cap-js/db-service
- Critical24 Apr 20262 packages tracked
elementary-data PyPI package backdoored via GitHub Actions injection
An attacker (account
realtungtungtungsahur) exploited a script-injection flaw in theelementary-datarelease workflow via PR comment, then used the workflow token to forge release commit b1e4b1f3 and trigger the legitimate publishing pipeline. PyPIelementary-data0.23.3 and ghcr.io/elementary-data/elementary 0.23.3 +latestshipped a ~245 KB obfuscated payload inelementary.pth. Clean 0.23.4 published April 25.DockerPyPIAffected packages2 packages · 3 versions
- PyPIelementary-data0.23.3
- Dockerghcr.io/elementary-data/elementary0.23.3latest
pypi-2026-04-24-elementary-dataSource advisory - PyPIelementary-data
- High23 Apr 20261 package tracked
js-logger-pack npm worm uses Hugging Face datasets as malware CDN + exfil store
JFrog found 27 malicious versions of
js-logger-pack(1.1.0-1.1.27) abusing the Hugging Face repoLordplay/system-releasesto fetch cross-platform binaries (Windows/macOS x64/macOS ARM64/Linux) and upload stolen data to private datasets. The malware adds keylogging, clipboard capture, browser-session and Telegram Desktop theft, plus an operator command channel.npmAffected packages1 package · 28 versions
- npmjs-logger-pack1.1.01.1.11.1.21.1.31.1.41.1.51.1.61.1.71.1.81.1.91.1.101.1.111.1.121.1.131.1.141.1.151.1.161.1.171.1.181.1.191.1.201.1.211.1.221.1.231.1.241.1.251.1.261.1.27
npm-2026-04-23-js-logger-pack-huggingfaceSource advisory - npmjs-logger-pack
- Critical22 Apr 20261 package tracked
Xinference PyPI package backdoored on import
JFrog flagged three consecutive
xinferencereleases (2.6.0-2.6.2) on PyPI carrying a TeamPCP-style payload embedded inxinference/__init__.pythat fires on import. The malware base64-encodes a stage-1 wrapper containing the comment# hacked by teampcp, then spawns a detached subprocess that bundles harvested data intolove.tar.gzand POSTs it with a customX-QT-SR: 14header. TeamPCP publicly denied involvement, claiming a copycat. 600,000+ downloads of malicious wheels.PyPIAffected packages1 package · 3 versions
- PyPIxinference2.6.02.6.12.6.2
pypi-2026-04-22-xinference-teampcpSource advisory - PyPIxinference
- Critical22 Apr 20263 packages tracked
Checkmarx KICS Docker images + Open VSX extensions compromised (TeamPCP)
Docker and Socket jointly disclosed a multi-stage compromise of Checkmarx KICS Docker images and Checkmarx VS Code / Open VSX extensions. Trojanised extensions silently install an MCP addon executed via Bun, while the Docker images include a modified KICS binary that encrypts scan output and exfiltrates it. TeamPCP claimed responsibility.
DockerOpen VSXAffected packages3 packages · 11 versions
- Open VSXcheckmarx.ast-results2.63.02.66.0
- Open VSXcheckmarx.cx-dev-assist1.17.01.19.0
- Dockercheckmarx/kics2.1.202.1.20-debian2.1.212.1.21-debianalpinedebianlatest
multi-2026-04-22-checkmarx-kics-vsx-dockerSource advisory - Open VSXcheckmarx.ast-results
- Critical22 Apr 20261 package tracked
@bitwarden/cli 2026.4.0 hijacked via Checkmarx GitHub Actions breach
TeamPCP pushed a malicious
@bitwarden/cli@2026.4.0to npm between 17:57 and 19:30 ET on April 22, exploiting Bitwarden's use of the breachedcheckmarx/ast-github-action.bw_setup.jsfetched Bun 1.3.13 from GitHub and ran a payload that targeted SSH, Git, npm, AWS/GCP/Azure, GitHub Actions secrets, and AI/MCP configs (.claude.json,.kiro/settings/mcp.json), exfiltrating viaaudit.checkmarx.cx. Live ~90 minutes; Bitwarden confirmed no end-user vault data was accessed.npmAffected packages1 package · 1 version
- npm@bitwarden/cli2026.4.0
npm-2026-04-22-bitwarden-cli-teampcpSource advisory - npm@bitwarden/cli
- Critical21 Apr 20266 packages tracked
CanisterSprawl: self-propagating npm worm hits pgserve + Namastex packages
Socket and StepSecurity disclosed CanisterSprawl, a self-propagating npm worm that compromised at least 16 versions across Namastex Labs and related publishers from 21 April 2026. The postinstall hook harvests 38 env vars and filesystem secrets, encrypts via AES-256-CBC + RSA-4096, and exfiltrates to an Internet Computer Protocol canister. Stolen npm tokens are reused to publish further malicious versions. Tradecraft matches the earlier TeamPCP CanisterWorm campaign.
npmAffected packages6 packages · 16 versions
- npm@automagik/genie4.260421.334.260421.344.260421.354.260421.364.260421.374.260421.384.260421.39
- npm@fairwords/loopback-connector-es1.4.31.4.4
- npm@fairwords/websocket1.0.381.0.39
- npm@openwebconcept/design-tokens1.0.3
- npm@openwebconcept/theme-owc1.0.3
- npmpgserve1.1.111.1.121.1.13
npm-2026-04-21-canisterworm-pgserve-namastexSource advisory - npm@automagik/genie
- High15 Apr 202636 packages tracked
36 fake Strapi plugins on npm deploy persistent implants
Four sock-puppet npm accounts (umarbek1233, kekylf12, tikeqemif26, umar_bektembiev1) uploaded 36 packages over a ~13-hour window impersonating Strapi CMS plugins. Payload evolution moved through 8 variants targeting Redis RCE with cron injection, Docker container escapes, PostgreSQL exploitation on hosts named
prod-strapi, Python reverse shells on port 4444, and SSH-key backdoors.npmAffected packages36 packages · 0 versions
- npmstrapi-plugin-advanced-uuid
- npmstrapi-plugin-api
- npmstrapi-plugin-blurhash
- npmstrapi-plugin-cms-tools
- npmstrapi-plugin-config
- npmstrapi-plugin-content-sync
- npmstrapi-plugin-core
- npmstrapi-plugin-cron
- npmstrapi-plugin-database
- npmstrapi-plugin-debug-tools
- npmstrapi-plugin-events
- npmstrapi-plugin-finseven
- npmstrapi-plugin-form
- npmstrapi-plugin-guardarian-ext
- npmstrapi-plugin-health
- npmstrapi-plugin-health-check
- npmstrapi-plugin-hextest
- npmstrapi-plugin-hooks
- npmstrapi-plugin-locale
- npmstrapi-plugin-logger
- npmstrapi-plugin-monitor
- npmstrapi-plugin-nordica
- npmstrapi-plugin-nordica-api
- npmstrapi-plugin-nordica-cms
- npmstrapi-plugin-nordica-deep
- npmstrapi-plugin-nordica-lite
- npmstrapi-plugin-nordica-recon
- npmstrapi-plugin-nordica-stage
- npmstrapi-plugin-nordica-sync
- npmstrapi-plugin-nordica-tools
- npmstrapi-plugin-nordica-vhost
- npmstrapi-plugin-notify
- npmstrapi-plugin-seed
- npmstrapi-plugin-server
- npmstrapi-plugin-sitemap-gen
- npmstrapi-plugin-sync
npm-2026-04-15-strapi-pluginsSource advisory - High15 Apr 20261 package tracked
@kindo/selfbot npm package delivers XWorm RAT via 5-stage Astral Warfare chain
JFrog identified
@kindo/selfbot(XRAY-964727), a video-game-themed Discord selfbot npm package. A 5-stage chain (JS downloader → 250KB obfuscated batch → PowerShell process injection → XOR-decoded shellcode → XWormClient .NET RAT) installed itself againstexplorer.exewith AMSI/ETW evasion.npmAffected packages1 package · 5 versions
- npm@kindo/selfbot1.0.01.0.11.0.21.0.31.0.4
npm-2026-04-15-kindo-selfbot-xwormSource advisory - npm@kindo/selfbot
- High14 Apr 20265 packages tracked
5 NuGet packages impersonate Chinese .NET UI libraries with infostealer payload
NuGet publisher
bmrxntfjshipped five packages on 14 April 2026 within ~13 seconds, grafting a .NET Reactor-protected infostealer onto decompiled legitimate libraries. Across 219 total versions they accumulated ~65k downloads, targeting browser creds, crypto wallets, and SSH keys on Windows .NET dev hosts.NuGetAffected packages5 packages · 5 versions
- NuGetIR.DantUI2.1.55
- NuGetIR.Infrastructure.Core2.1.55
- NuGetIR.Infrastructure.DataService.Core2.1.55
- NuGetIR.iplus322.1.55
- NuGetIR.OscarUI2.1.55
nuget-2026-04-14-chinese-ui-impersonatorsSource advisory - NuGetIR.DantUI
- High7 Apr 202614 packages tracked
DPRK Contagious Interview campaign expands across 5 ecosystems
Socket disclosed a fresh wave of DPRK Contagious Interview / FAMOUS CHOLLIMA packages spanning npm, PyPI, Go modules, crates.io, and Packagist. They impersonate logging / license developer tooling and act as staged loaders for credential stealers and RATs across Windows, macOS and Linux. The Windows variant deploys a keylogger and AnyDesk for hands-on access.
crates.ioGonpmPackagistPyPIAffected packages14 packages · 6 versions
- PyPIapachelicense0.1a1
- npmdebug-fmt
- npmdebug-glitz
- npmdev-log-core1.0.5
- PyPIfluxhttp
- Gogithub.com/aokisasakidev/mit-license-pkg1.0.2
- Gogithub.com/golangorg/formstash1.0.5
- Packagistgolangorg/logkit
- PyPIlicense-utils-kit0.1rc3
- npmlogger-base
- npmlogkitx
- crates.iologtrace1.0.2
- PyPIlogutilkit
- npmpino-debugger
multi-2026-04-07-contagious-interview-5-ecosystemsSource advisory - PyPIapachelicense
- Medium5 Apr 20261 package tracked
hermes-px PyPI "privacy" AI proxy steals prompts via stolen university infra
JFrog detected
hermes-px, masquerading as a privacy-preserving AI proxy. It routed requests through Tor to a stolen Tunisian university API and bundled a 246K-character Anthropic Claude system prompt rebranded as "AXIOM-1". It simultaneously exfiltrated all prompts/responses unencrypted to a Supabase endpoint, bypassing Tor and exposing user IPs.PyPIAffected packages1 package · 0 versions
- PyPIhermes-px
pypi-2026-04-05-hermes-pxSource advisory - Critical31 Mar 20264 packages tracked
Axios npm compromise (North Korea-nexus RAT)
Lead-maintainer account compromised via social engineering. Two malicious axios releases pulled in plain-crypto-js, whose postinstall fetched a cross-platform RAT from sfrclak[.]com:8000. Microsoft + Google attribute to Sapphire Sleet / UNC1069 (North Korea-nexus). Live for ~3 hours; ~100M weekly downloads in scope.
npmAffected packages4 packages · 8 versions
- npm@qqbrowser/openclaw-qbot0.0.130
- npm@shadanai/openclaw2026.3.28-22026.3.28-32026.3.31-12026.3.31-2
- npmaxios1.14.10.30.4
- npmplain-crypto-js4.2.1
npm-2026-03-axiosSource advisory - npm@qqbrowser/openclaw-qbot
- High31 Mar 20261 package tracked
LofyGang returns with undicy-http typosquat delivering dual-payload RAT
JFrog tied
undicy-http@2.0.0(a typosquat ofundici) to the Brazil-based LofyGang group last seen in 2022. The package pairs a Node.js WebSocket RAT with a nativechromelevator.exebinary that uses direct syscalls for process hollowing, then injects browser credential stealers targeting 50+ browsers and 90+ wallet extensions.npmAffected packages1 package · 1 version
- npmundicy-http2.0.0
npm-2026-03-31-undicy-lofygangSource advisory - npmundicy-http
- Critical27 Mar 20261 package tracked
Telnyx Python SDK hides credential stealer in WAV-file steganography
TeamPCP published malicious
telnyx4.87.1 and 4.87.2 to PyPI on 27 March 2026 (~670k monthly downloads). Trojanised_client.pydownloads steganographic payloads disguised as.wavfiles over plaintext HTTP, extracts the credential stealer, and persists. Windows variant dropsmsbuild.exeto the Startup folder; Linux variant uses a user-level systemd service. AES-256-CBC + RSA-4096 envelope for exfil.PyPIAffected packages1 package · 2 versions
- PyPItelnyx4.87.14.87.2
pypi-2026-03-27-telnyx-teampcpSource advisory - PyPItelnyx
- Critical24 Mar 20261 package tracked
LiteLLM PyPI backdoored as TeamPCP cascade reaches Python
TeamPCP used credentials harvested from the Trivy compromise to publish trojanised
litellm1.82.7 and 1.82.8 to PyPI on 24 March 2026 (~10:39 and 10:52 UTC). Malicious wheels drop alitellm_init.pthfile in site-packages, executing a credential stealer at every Python interpreter start. PyPI quarantined the packages ~40 minutes after publication. Attackers later claimed ~500,000 credentials from this single compromise. LiteLLM averages ~3M daily downloads and ships in ~36% of cloud environments.PyPIAffected packages1 package · 2 versions
- PyPIlitellm1.82.71.82.8
pypi-2026-03-24-litellm-teampcpSource advisory - PyPIlitellm
- High24 Mar 20265 packages tracked
5 npm typosquats target Solana + Ethereum dev libraries, exfil keys to Telegram
npm publisher
galedonovanshipped five typosquats of legitimate crypto libraries. Each transparently intercepts private keys passed through normal API calls (Base58 decoding for Solana, Wallet construction for Ethereum), exfiltrates them to a hardcoded Telegram bot, then returns the expected result so functionality looks normal.npmAffected packages5 packages · 4 versions
- npmbase_xd
- npmbase-x-640.0.6
- npmbs58-basic6.0.1
- npmethersproject-wallet5.8.1
- npmraydium-bs581.9.7
npm-2026-03-24-solana-ethereum-typosquatsSource advisory - High23 Mar 20262 packages tracked
Checkmarx KICS GitHub Actions trojanised by TeamPCP
Between 12:58 and 16:50 UTC on 23 March 2026, TeamPCP hijacked 35 tags in the Checkmarx
ast-github-actionandkics-github-actionrepos to push a credential stealer, leveraging tokens stolen from the Trivy compromise. CI/CD pipelines using either Action during the window executed the stealer before the legitimate scan.GitHub ActionsAffected packages2 packages · 0 versions
- GitHub Actionscheckmarx/ast-github-action
- GitHub Actionscheckmarx/kics-github-action
github-actions-2026-03-23-checkmarx-kicsSource advisory - Critical20 Mar 202629 packages tracked
CanisterWorm: @emilgroup and @teale.io npm publisher compromise (29+ packages)
An attacker compromised the @emilgroup and @teale.io npm namespaces, replacing 58 package-versions with a Python backdoor that polls an Internet Computer Protocol (ICP) canister for follow-on payloads. The implant persists via user-level systemd and includes worm-style republishing via deploy.js. Wiz later linked the tradecraft to TeamPCP; Socket declined firm attribution.
npmAffected packages29 packages · 58 versions
- npm@emilgroup/account-sdk1.41.11.41.2
- npm@emilgroup/account-sdk-node1.40.11.40.2
- npm@emilgroup/accounting-sdk-node1.26.11.26.2
- npm@emilgroup/api-documentation1.19.11.19.2
- npm@emilgroup/auth-sdk1.25.11.25.2
- npm@emilgroup/auth-sdk-node1.21.11.21.2
- npm@emilgroup/billing-sdk1.56.11.56.2
- npm@emilgroup/billing-sdk-node1.57.11.57.2
- npm@emilgroup/claim-sdk1.41.11.41.2
- npm@emilgroup/claim-sdk-node1.39.11.39.2
- npm@emilgroup/customer-sdk1.54.11.54.2
- npm@emilgroup/customer-sdk-node1.55.11.55.2
- npm@emilgroup/document-sdk1.45.11.45.2
- npm@emilgroup/document-sdk-node1.43.11.43.2
- npm@emilgroup/gdv-sdk2.6.12.6.2
- npm@emilgroup/insurance-sdk1.97.11.97.2
- npm@emilgroup/insurance-sdk-node1.95.11.95.2
- npm@emilgroup/notification-sdk-node1.4.11.4.2
- npm@emilgroup/partner-portal-sdk-node1.1.11.1.2
- npm@emilgroup/partner-sdk-node1.19.11.19.2
- npm@emilgroup/payment-sdk1.15.11.15.2
- npm@emilgroup/payment-sdk-node1.23.11.23.2
- npm@emilgroup/process-manager-sdk-node1.13.11.13.2
- npm@emilgroup/public-api-sdk1.33.11.33.2
- npm@emilgroup/public-api-sdk-node1.35.11.35.2
- npm@emilgroup/tenant-sdk1.34.11.34.2
- npm@emilgroup/tenant-sdk-node1.33.11.33.2
- npm@emilgroup/translation-sdk-node1.1.11.1.2
- npm@teale.io/eslint-config1.8.91.8.10
npm-2026-03-20-canisterworm-emilgroup-tealeSource advisory - npm@emilgroup/account-sdk
- Critical19 Mar 20263 packages tracked
Trivy GitHub Action + Docker images compromised - start of TeamPCP cascade
Aqua Security's Trivy scanner was compromised on 19 March 2026 by the threat actor self-identifying as TeamPCP. The attacker force-pushed 76 of 77 tags in
aquasecurity/trivy-action(only @0.35.0 survived) and all 7 tags inaquasecurity/setup-trivyto malicious commits, then published trojanised Trivy binary 0.69.4 + Docker images 0.69.5/0.69.6/latest. A stolen Argon-DevOps-Mgt service-account token seeded the downstream LiteLLM, Telnyx, Bitwarden CLI, and Checkmarx compromises.DockerGitHub ActionsAffected packages3 packages · 4 versions
- Dockeraquasec/trivy0.69.40.69.50.69.6latest
- GitHub Actionsaquasecurity/setup-trivy
- GitHub Actionsaquasecurity/trivy-action
github-actions-2026-03-19-trivy-teampcp-cascadeSource advisory - Dockeraquasec/trivy
- High18 Mar 20262 packages tracked
GlassWorm sleeper extensions activate on Open VSX
Roughly 40 malicious VS Code extensions surfaced March 14-18, 2026: 20+ new extensions, ~20 previously dormant sleepers activated, plus 11 extensionPack droppers. The campaign hosts VSIX payloads on attacker-controlled GitHub releases to evade registry takedowns. Publishing accounts:
laura6909,martina0094,chiara585,francesca898.Open VSXAffected packages2 packages · 3 versions
- Open VSX96-studio.json-formatter0.0.20.0.4
- Open VSXlauracode.wrap-selected-code0.0.2
openvsx-2026-03-18-glassworm-sleeperSource advisory - Open VSX96-studio.json-formatter
- High13 Mar 2026Feed-only · no version-specific detection
GlassWorm: 72+ Open VSX extensions weaponised via transitive loaders
Socket linked at least 72 additional malicious Open VSX extensions to the GlassWorm campaign. Newer variants use
extensionPack/extensionDependenciesfields to transitively pull GlassWorm loaders rather than embedding malware directly. Obfuscation rotated to RC4 + base64 with keys delivered in HTTP response headers.openvsx-2026-03-13-glassworm-transitiveSource advisory - Medium12 Mar 20266 packages tracked
6 malicious Packagist OphimCMS themes ship trojanised jQuery and FUNNULL redirects
Six Composer packages from the
ophimcmsorganisation posed as OphimCMS themes containing trojanised jQuery. The payload exfiltrates URLs, injects ads, and redirects mobile traffic via OFAC-sanctioned FUNNULL infrastructure. Combined ~2,750 installs.PackagistAffected packages6 packages · 6 versions
- Packagistophimcms/theme-dy1.0.0
- Packagistophimcms/theme-legend1.0.0
- Packagistophimcms/theme-motchill1.0.0
- Packagistophimcms/theme-mtyy1.0.0
- Packagistophimcms/theme-pcc1.2.2
- Packagistophimcms/theme-rrdyw1.0.0
packagist-2026-03-12-ophimcms-themesSource advisory - Packagistophimcms/theme-dy
- Medium28 Feb 20265 packages tracked
5 malicious Rust crates pose as time utilities to exfiltrate .env files
Five crates published between late February and early March 2026 posed as local time utilities while exfiltrating .env files via
curlto a lookalike domaintimeapis.io(typosquattingtimeapi.io). All packages were 0.1.0 and yanked within hours. Account aliases:gehakax777,dictorudin.crates.ioAffected packages5 packages · 5 versions
- crates.iochrono_anchor0.1.0
- crates.iodnp3times0.1.0
- crates.iotime_calibrator0.1.0
- crates.iotime_calibrators0.1.0
- crates.iotime-sync0.1.0
crates-2026-02-28-time-utility-typosquatsSource advisory - crates.iochrono_anchor
- High27 Feb 202626 packages tracked
StegaBin: 26 npm typosquats use Pastebin steganography to deliver Contagious Interview RAT
Socket disclosed 26 typosquatted npm packages tied to North Korea's Contagious Interview / FAMOUS CHOLLIMA cluster. The loader decodes steganographically-encoded Pastebin URLs to resolve C2 hosted across 31 Vercel deployments, then retrieves a 9-module infostealer and RAT toolkit.
npmAffected packages26 packages · 26 versions
- npmargonist0.41.0
- npmbcryptance6.5.2
- npmbee-quarl2.1.2
- npmbubble-core6.26.2
- npmcorstoken2.14.7
- npmdaytonjs1.11.20
- npmether-lint5.9.4
- npmexpressjs-lint5.3.2
- npmfastify-lint5.8.0
- npmformmiderable3.5.7
- npmhapi-lint19.1.2
- npmiosysredis5.13.2
- npmjslint-config10.22.2
- npmjsnwebapptoken8.40.2
- npmkafkajs-lint2.21.3
- npmloadash-lint4.17.24
- npmmqttoken5.40.2
- npmprism-lint7.4.2
- npmpromanage6.0.21
- npmsequelization6.40.2
- npmtyporiem0.4.17
- npmundicy-lint7.23.1
- npmuuindex13.1.0
- npmvitetest-lint4.1.21
- npmwindowston3.19.2
- npmzoddle4.4.2
npm-2026-02-27-stegabin-contagious-interviewSource advisory - npmargonist
- Critical20 Feb 202619 packages tracked
SANDWORM_MODE: 19 npm typosquats with self-spreading worm + AI toolchain poisoning
Socket disclosed a Shai-Hulud-style self-propagating worm spread across at least 19 typosquatted npm packages from accounts
official334andjavaorg. It harvests CI secrets and crypto keys, propagates via stolen npm/GitHub tokens, and injects prompt-injection logic into MCP servers used by AI coding assistants.npmAffected packages19 packages · 19 versions
- npmclaud-code0.2.1
- npmcloude0.3.0
- npmcloude-code0.2.1
- npmcrypto-locale1.0.0
- npmcrypto-reader-info1.0.0
- npmdetect-cache1.0.0
- npmformat-defaults1.0.0
- npmhardhta1.0.0
- npmlocale-loader-pro1.0.0
- npmnaniod1.0.0
- npmnode-native-bridge1.0.0
- npmopencraw2026.2.17
- npmparse-compat1.0.0
- npmrimarf1.0.0
- npmscan-store1.0.0
- npmsecp2561.0.0
- npmsuport-color1.0.1
- npmveim2.46.2
- npmyarsg18.0.1
npm-2026-02-20-sandworm-modeSource advisory - npmclaud-code
- High17 Feb 20261 package tracked
cline npm package hijacked via "Clinejection" prompt-injection chain
An attacker abused an unsanitised AI issue-triage GitHub Actions workflow on the Cline repo to poison the release pipeline cache and steal the npm publish token. They published
cline@2.3.0with a postinstall script that globally installed the second-stage packageopenclaw. ~90k weekly downloads; live for ~8 hours before Cline rotated the token and shipped 2.4.0.npmAffected packages1 package · 1 version
- npmcline2.3.0
npm-2026-02-17-cline-clinejectionSource advisory - npmcline
- High11 Feb 202630 packages tracked
Lazarus "graphalgo" fake-recruiter campaign (npm + PyPI)
ReversingLabs attributed an ongoing fake-recruiter campaign (active since May 2025, reported Feb 2026) to North Korea's Lazarus Group (overlapping Jade Sleet / UNC4899). Crypto, JavaScript, and Python developers are lured via LinkedIn/Reddit/Facebook into interview "coding tasks" that pull a token-protected RAT loader from npm and PyPI. ~192 malicious packages attributed in total; bigmathutils alone passed 10,000 downloads.
npmPyPIAffected packages30 packages · 44 versions
- npmbigmathex
- npmbigmathix
- npmbigmathlib
- npmbigmathutils1.0.01.1.0
- npmbignumberx
- npmbignumex
- npmbignumx
- PyPIbigpyx
- npmgraphalgo2.2.5-pre2.2.62.2.72.2.82.2.92.2.102.2.11
- PyPIgraphalgo-py3.5.1rc0.dev03.5.23.5.33.5.53.5.6
- npmgraphchain
- PyPIgraphdict
- PyPIgraphex3.5.73.5.83.5.93.5.10
- npmgraphflowx
- npmgraphflux
- npmgraphhub
- npmgraphkitx
- npmgraphlibcore2.2.62.2.72.2.82.2.92.2.102.2.11
- PyPIgraphlibx
- npmgraphnet
- npmgraphnetworkx2.1.62.1.72.1.82.1.92.1.102.1.11
- PyPIgraphnode
- npmgraphorbit
- npmgraphorithm2.2.62.2.72.2.82.2.9
- npmgraphrix
- npmgraphstruct2.2.62.2.72.2.8
- PyPIgraphsync
- npmnetstruct2.1.62.1.8
- npmterminal-kleur
- npmterminalcolor2562.0.22.0.32.1.02.2.02.2.6
multi-2026-02-11-lazarus-graphalgoSource advisory - Medium5 Feb 20263 packages tracked
Polymarket SDK typosquats on crates.io
Three crates impersonating
polymarket-client-sdkwere published between 5 and 19 February 2026 and exfiltrated local credential files. The malicious crates were yanked and publisher accounts disabled. Combined downloads stayed under 100, but targeting was high-value (Polymarket / Web3 developers).crates.ioAffected packages3 packages · 0 versions
- crates.iopolymarket-client-sdks
- crates.iopolymarket-clients-sdk
- crates.iopolymarkets-client-sdk
crates-2026-02-05-polymarket-typosquatsSource advisory - Critical27 Jan 20262 packages tracked
dYdX v4-client npm + PyPI compromise (wallet stealer + RAT)
Maintainer credentials for the dYdX decentralized exchange were compromised; malicious versions of the official v4 client were pushed to npm and PyPI in a coordinated release. The npm payload exfiltrates wallet seed phrases through a malicious
createRegistry()function. The PyPI variant additionally drops a Python RAT executed on import.npmPyPIAffected packages2 packages · 6 versions
- npm@dydxprotocol/v4-client-js1.0.311.15.21.22.13.4.1
- PyPIdydx-v4-client1.1.5.post11.1.5post1
multi-2026-01-27-dydx-compromiseSource advisory - npm@dydxprotocol/v4-client-js
- High17 Jan 20261 package tracked
sympy-dev PyPI typosquat delivering XMRig cryptominer
A PyPI typosquat of SymPy was published by the account "Nanit" across four versions on Jan 17, 2026. It fetches a remote JSON config, downloads an ELF, and executes it from a memfd to evade disk-based detection. The payload is XMRig mining Monero on infected developer workstations.
PyPIAffected packages1 package · 4 versions
- PyPIsympy-dev1.2.31.2.41.2.51.2.6
pypi-2026-01-17-sympy-dev-minerSource advisory - PyPIsympy-dev
- Critical15 Sept 2025197 packages tracked
Original Shai-Hulud npm worm
First successful self-propagating worm in the npm ecosystem. Downstream of the August 2025 s1ngularity/Nx GitHub-token theft. The postinstall hook ran TruffleHog to harvest secrets, opened public GitHub repos named "Shai-Hulud" to publish them, force-converted private repos to public with a "-migration" suffix, and used stolen npm tokens to publish malicious versions of any package the maintainer could access. ~180 unique packages compromised across 300+ versions, including CrowdStrike's own scope (@crowdstrike/*).
npmAffected packages197 packages · 509 versions
- npm@ahmedhfarag/ngx-perfect-scrollbar20.0.20
- npm@ahmedhfarag/ngx-virtual-scroller4.0.4
- npm@art-ws/common2.0.28
- npm@art-ws/config-eslint2.0.42.0.5
- npm@art-ws/config-ts2.0.72.0.8
- npm@art-ws/db-context2.0.24
- npm@art-ws/di2.0.282.0.32
- npm@art-ws/di-node2.0.13
- npm@art-ws/eslint1.0.51.0.6
- npm@art-ws/fastify-http-server2.0.242.0.27
- npm@art-ws/http-server2.0.212.0.25
- npm@art-ws/openapi0.1.90.1.12
- npm@art-ws/package-base1.0.51.0.6
- npm@art-ws/prettier1.0.51.0.6
- npm@art-ws/slf2.0.152.0.22
- npm@art-ws/ssl-info1.0.91.0.10
- npm@art-ws/web-app1.0.31.0.4
- npm@basic-ui-components-stc/basic-ui-components1.0.5
- npm@crowdstrike/commitlint8.1.18.1.2
- npm@crowdstrike/falcon-shoelace0.4.10.4.2
- npm@crowdstrike/foundry-js0.19.10.19.2
- npm@crowdstrike/glide-core0.34.20.34.3
- npm@crowdstrike/logscale-dashboard1.205.11.205.2
- npm@crowdstrike/logscale-file-editor1.205.11.205.2
- npm@crowdstrike/logscale-parser-edit1.205.11.205.2
- npm@crowdstrike/logscale-search1.205.11.205.2
- npm@crowdstrike/tailwind-toucan-base5.0.15.0.2
- npm@ctrl/deluge7.2.17.2.2
- npm@ctrl/golang-template1.4.21.4.3
- npm@ctrl/magnet-link4.0.34.0.4
- npm@ctrl/ngx-codemirror7.0.17.0.2
- npm@ctrl/ngx-csv6.0.16.0.2
- npm@ctrl/ngx-emoji-mart9.2.19.2.2
- npm@ctrl/ngx-rightclick4.0.14.0.2
- npm@ctrl/qbittorrent9.7.19.7.2
- npm@ctrl/react-adsense2.0.12.0.2
- npm@ctrl/shared-torrent6.3.16.3.2
- npm@ctrl/tinycolor4.1.14.1.2
- npm@ctrl/torrent-file4.1.14.1.2
- npm@ctrl/transmission7.3.1
- npm@ctrl/ts-base324.0.14.0.2
- npm@hestjs/core0.2.1
- npm@hestjs/cqrs0.1.6
- npm@hestjs/demo0.1.2
- npm@hestjs/eslint-config0.1.2
- npm@hestjs/logger0.1.6
- npm@hestjs/scalar0.1.7
- npm@hestjs/validation0.1.6
- npm@nativescript-community/arraybuffers1.1.61.1.71.1.8
- npm@nativescript-community/gesturehandler2.0.35
- npm@nativescript-community/perms3.0.53.0.63.0.73.0.83.0.9
- npm@nativescript-community/sentry4.6.43
- npm@nativescript-community/sqlite3.5.23.5.33.5.43.5.5
- npm@nativescript-community/text1.6.91.6.101.6.111.6.121.6.13
- npm@nativescript-community/typeorm0.2.300.2.310.2.320.2.33
- npm@nativescript-community/ui-collectionview6.0.6
- npm@nativescript-community/ui-document-picker1.1.271.1.2813.0.32
- npm@nativescript-community/ui-drawer0.1.30
- npm@nativescript-community/ui-image4.5.6
- npm@nativescript-community/ui-label1.3.351.3.361.3.37
- npm@nativescript-community/ui-material-bottom-navigation7.2.727.2.737.2.747.2.75
- npm@nativescript-community/ui-material-bottomsheet7.2.72
- npm@nativescript-community/ui-material-core7.2.727.2.737.2.747.2.757.2.76
- npm@nativescript-community/ui-material-core-tabs7.2.727.2.737.2.747.2.757.2.76
- npm@nativescript-community/ui-material-ripple7.2.727.2.737.2.747.2.75
- npm@nativescript-community/ui-material-tabs7.2.727.2.737.2.747.2.75
- npm@nativescript-community/ui-pager14.1.3614.1.3714.1.38
- npm@nativescript-community/ui-pulltorefresh2.5.42.5.52.5.62.5.7
- npm@nexe/config-manager0.1.1
- npm@nexe/eslint-config0.1.1
- npm@nexe/logger0.1.3
- npm@nstudio/angular20.0.420.0.520.0.6
- npm@nstudio/focus20.0.420.0.520.0.6
- npm@nstudio/nativescript-checkbox2.0.62.0.72.0.82.0.9
- npm@nstudio/nativescript-loading-indicator5.0.15.0.25.0.35.0.4
- npm@nstudio/ui-collectionview5.1.115.1.125.1.135.1.14
- npm@nstudio/web20.0.4
- npm@nstudio/web-angular20.0.4
- npm@nstudio/xplat20.0.520.0.620.0.7
- npm@nstudio/xplat-utils20.0.520.0.620.0.7
- npm@operato/board9.0.369.0.379.0.389.0.399.0.409.0.419.0.429.0.439.0.449.0.459.0.46
- npm@operato/data-grist9.0.299.0.359.0.369.0.37
- npm@operato/graphql9.0.229.0.359.0.369.0.379.0.389.0.399.0.409.0.419.0.429.0.439.0.449.0.459.0.46
- npm@operato/headroom9.0.29.0.359.0.369.0.37
- npm@operato/help9.0.359.0.369.0.379.0.389.0.399.0.409.0.419.0.429.0.439.0.449.0.459.0.46
- npm@operato/i18n9.0.359.0.369.0.37
- npm@operato/input9.0.279.0.359.0.369.0.379.0.389.0.399.0.409.0.419.0.429.0.439.0.449.0.459.0.469.0.479.0.48
- npm@operato/layout9.0.359.0.369.0.37
- npm@operato/popup9.0.229.0.359.0.369.0.379.0.389.0.399.0.409.0.419.0.429.0.439.0.449.0.459.0.469.0.49
- npm@operato/pull-to-refresh9.0.369.0.379.0.389.0.399.0.409.0.419.0.42
- npm@operato/shell9.0.229.0.359.0.369.0.379.0.389.0.39
- npm@operato/styles9.0.29.0.359.0.369.0.37
- npm@operato/utils9.0.229.0.359.0.369.0.379.0.389.0.399.0.409.0.419.0.429.0.439.0.449.0.459.0.469.0.49
- npm@teselagen/bio-parsers0.4.290.4.30
- npm@teselagen/bounce-loader0.3.160.3.17
- npm@teselagen/file-utils0.3.210.3.22
- npm@teselagen/liquibase-tools0.4.1
- npm@teselagen/ove0.7.390.7.40
- npm@teselagen/range-utils0.3.140.3.15
- npm@teselagen/react-list0.8.190.8.20
- npm@teselagen/react-table6.10.196.10.206.10.216.10.22
- npm@teselagen/sequence-utils0.3.330.3.34
- npm@teselagen/ui0.9.90.9.10
- npm@thangved/callback-window1.1.4
- npm@things-factory/attachment-base9.0.429.0.439.0.449.0.459.0.469.0.479.0.489.0.499.0.509.0.519.0.529.0.539.0.549.0.55
- npm@things-factory/auth-base9.0.429.0.439.0.449.0.45
- npm@things-factory/email-base9.0.429.0.439.0.449.0.459.0.469.0.479.0.489.0.499.0.509.0.519.0.529.0.539.0.549.0.559.0.569.0.579.0.589.0.59
- npm@things-factory/env9.0.429.0.439.0.449.0.45
- npm@things-factory/integration-base9.0.429.0.439.0.449.0.45
- npm@things-factory/integration-marketplace9.0.429.0.439.0.449.0.45
- npm@things-factory/shell9.0.429.0.439.0.449.0.45
- npm@tnf-dev/api1.0.8
- npm@tnf-dev/core1.0.8
- npm@tnf-dev/js1.0.8
- npm@tnf-dev/mui1.0.8
- npm@tnf-dev/react1.0.8
- npm@ui-ux-gang/devextreme-angular-rpk24.1.7
- npm@yoobic/design-system6.5.17
- npm@yoobic/jpeg-camera-es61.0.13
- npm@yoobic/yobi8.7.53
- npmairchief0.3.1
- npmairpilot0.8.8
- npmangulartics214.1.114.1.2
- npmbrowser-webdriver-downloader3.0.8
- npmcapacitor-notificationhandler0.0.20.0.3
- npmcapacitor-plugin-healthapp0.0.20.0.3
- npmcapacitor-plugin-ihealth1.1.81.1.9
- npmcapacitor-plugin-vonage1.0.21.0.3
- npmcapacitorandroidpermissions0.0.40.0.5
- npmconfig-cordova0.8.5
- npmcordova-plugin-voxeet21.0.24
- npmcordova-voxeet1.0.32
- npmcreate-hest-app0.1.9
- npmdb-evo1.1.41.1.5
- npmdevextreme-angular-rpk21.2.8
- npmdevextreme-rpk21.2.8
- npmember-browser-services5.0.25.0.3
- npmember-headless-form1.1.21.1.3
- npmember-headless-form-yup1.0.1
- npmember-headless-table2.1.52.1.6
- npmember-url-hash-polyfill1.0.121.0.13
- npmember-velcro2.2.12.2.2
- npmencounter-playground0.0.20.0.30.0.40.0.5
- npmeslint-config-crowdstrike11.0.211.0.3
- npmeslint-config-crowdstrike-node4.0.34.0.4
- npmeslint-config-teselagen6.1.76.1.8
- npmglobalize-rpk1.7.4
- npmgraphql-sequelize-teselagen5.3.85.3.9
- npmhtml-to-base64-image1.0.2
- npmjson-rules-engine-simplified0.2.10.2.30.2.4
- npmjumpgate0.0.2
- npmkoa2-swagger-ui5.11.15.11.2
- npmmcfly-semantic-release1.3.1
- npmmcp-knowledge-base0.0.2
- npmmcp-knowledge-graph1.2.1
- npmmobioffice-cli1.0.3
- npmmonorepo-next13.0.113.0.2
- npmmstate-angular0.4.4
- npmmstate-cli0.4.7
- npmmstate-dev-react1.1.1
- npmmstate-react1.6.5
- npmng2-file-upload7.0.27.0.38.0.18.0.28.0.39.0.1
- npmngx-bootstrap18.1.419.0.319.0.420.0.320.0.420.0.520.0.6
- npmngx-color10.0.110.0.2
- npmngx-toastr19.0.119.0.2
- npmngx-trend8.0.1
- npmngx-ws1.1.51.1.6
- npmoradm-to-gql35.0.1435.0.15
- npmoradm-to-sqlz1.1.21.1.4
- npmove-auto-annotate0.0.90.0.10
- npmpm2-gelf-json1.0.41.0.5
- npmprintjs-rpk1.6.1
- npmreact-complaint-image0.0.320.0.340.0.35
- npmreact-jsonschema-form-conditionals0.3.180.3.200.3.21
- npmreact-jsonschema-form-extras1.0.31.0.4
- npmreact-jsonschema-rxnt-extras0.4.80.4.9
- npmremark-preset-lint-crowdstrike4.0.14.0.2
- npmrxnt-authentication0.0.30.0.40.0.50.0.6
- npmrxnt-healthchecks-nestjs1.0.21.0.31.0.41.0.5
- npmrxnt-kue1.0.41.0.51.0.61.0.7
- npmswc-plugin-component-annotate1.9.11.9.2
- npmtbssnch1.0.2
- npmteselagen-interval-tree1.1.2
- npmtg-client-query-builder2.14.42.14.5
- npmtg-redbird1.3.11.3.2
- npmtg-seq-gen1.0.91.0.10
- npmthangved-react-grid1.0.3
- npmts-gaussian3.0.53.0.6
- npmts-imports1.0.11.0.2
- npmtvi-cli0.1.5
- npmve-bamreader0.2.60.2.7
- npmve-editor1.0.11.0.2
- npmverror-extra6.0.1
- npmvoip-callkit1.0.21.0.3
- npmwdio-web-reporter0.1.3
- npmyargs-help-output5.0.3
- npmyoo-styles6.0.326
npm-2025-09-shai-hulud-originalSource advisory - npm@ahmedhfarag/ngx-perfect-scrollbar
Sources cited per card. We only list package versions named by the original advisory; we don't infer compromises. Missing something? Send it in.